[dns-operations] First experiments with DNS dampening to fight amplification attacks

Dobbins, Roland rdobbins at arbor.net
Mon Oct 29 10:21:46 UTC 2012

On Oct 29, 2012, at 5:16 PM, Stephane Bortzmeyer wrote:

> ? iptables != stateful firewalling. 

I've only ever seen it deployed with connection tracking - i.e., statefully.  You're right, though, that isn't a requirement.

Roland Dobbins <rdobbins at arbor.net> // <http://www.arbornetworks.com>

	  Luck is the residue of opportunity and design.

		       -- John Milton

More information about the dns-operations mailing list