[j-nsp] DDoS protection for J-series and SRX

Morgan McLean wrx230 at gmail.com
Fri Apr 12 04:47:51 EDT 2013


Cloudflare :)


On Fri, Apr 12, 2013 at 12:49 AM, James Howlett <jim.howlett at outlook.com>wrote:

> Hello,
>
> >
> > Definitely SCREENs, as other folks have said.
> >
> > However, in the corner case where you're getting traffic for a
> > particular service or destination IP that isn't in use (maybe not in
> > this instance), a quick way of protecting the traffic from hitting the
> > flow module is to use a firewall filter with a discard action for that
> > traffic.
> >
> > Just something to keep in your toobox..
> >
>
> What about a scenario, when suddenly I get 100 000 new pps . Then, no
> matter the scenario my SRX will die.
> Is there anything one can do here?
>
> All best,
> jim
>
> _______________________________________________
> juniper-nsp mailing list juniper-nsp at puck.nether.net
> https://puck.nether.net/mailman/listinfo/juniper-nsp
>



-- 
Thanks,
Morgan


More information about the juniper-nsp mailing list