[dns-operations] DDOS/Collateral Damage BCPs

Phil Regnauld regnauld at nsrc.org
Thu Apr 15 19:28:50 UTC 2010


Barry Raveendran Greene (bgreene) writes:
> 
> Q. Has anyone done any recent work on "architecture" guides for SP's DNS?
> This crew is using bind, they are cluefull enough to break apart their
> customer resolvers and the slaves, and are willing to make changes.

	Anycasting an Unbound setup works well -- just held a workshop
	on this for MENOG in Riyadh.

	What's the profile of the DDoS ?  Any identifiable denominator in the
	queries that would make it easier to filter on the upstreams ?

	More info appreciated, eventually off-list.



More information about the dns-operations mailing list