[j-nsp] Juniper Product against DDoS

Darius Jahandarie djahandarie at gmail.com
Tue Feb 18 19:10:56 EST 2014


On Tue, Feb 18, 2014 at 10:08 AM, Dobbins, Roland <rdobbins at arbor.net> wrote:
> They also have flowspec capabilities on many (all?) of their routers; flowspec can be utilized to leverage the routers to mitigate DDoS attacks using layer-4 classification.

It is worth pointing out that no transit providers actually accept
flowspec. Mainly due to the flowspec code in Juniper being being
bit-rotted, bug-riddled, and slow.

So they only "have flowspec capabilities" for very limited meanings of
"have". :-(

-- 
Darius Jahandarie


More information about the juniper-nsp mailing list