Are there any "best practice" settings for specific OS/firewalls? I use FreeBSD and pf.
How to launch and defend against a DDoS attack [pdf]
21–22 of 22 posts
Re: How to launch and defend against a DDoS attack [pdf]
#22Martian packets are a funny thing: The packet is ALWAYS coming from somewhere, so why don't internet providers just flat out refuse to send packets exiting their networks if the given IP doesn't match what they get? Okay, routers are supposed to get a packet and just route it to the next point by blindly following the instructions ("0.0.0.1 wants to UDP 124.40.28.9 on port 80"), but whatever the route taken, once my…
Reputable ones do check that (uRPF).
Get Ecatel's upstreams to cut their ports and you'll get rid of 80% of it.