[dns-operations] DNS Issue

Phil Regnauld regnauld at nsrc.org
Fri Apr 26 12:29:14 UTC 2013

Joe Abley (jabley) writes:
> The number of stateful firewalls that can happily handle occasional flows of up to 100,000 flows per second two/from individual devices are few. "Yours probably isn't one of them."

	Corollary: whatever device you'll be putting in front of the DNS servers
	to protect them probably won't be dealing so well with whatever conectivity
	you'll have a couple of years down the road. In general, vendors of
	attack mitigation equipment rarely advise you about what you'll need
	in the future, only what they can sell you now.


