[c-nsp] DNS amplification

Sander Steffann sander at steffann.nl
Sat Mar 16 17:46:15 EDT 2013


> Restrict resolvers to your customer networks. 

And if you have authoritative DNSSEC zones or other zones with large answers it might be a good idea to look at rate limiting the authoritative servers: http://www.redbarn.org/dns/ratelimits

- Sander




More information about the cisco-nsp mailing list