Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).
What makes you think OVH could cope with a 200 Gbps DoS attack of this nature? A quick look at their services indicates they don't mention what kind of attacks they defend against, and SYN floods are some of the hardest to defend against.
A DDoS in Asia Pacific
31–40 of 46 posts
Re: A DDoS in Asia Pacific
#32https://www.ietf.org/mail-archive/web/tcpm/current/msg08204....
Re: A DDoS in Asia Pacific
#33According to the founder [1], Telegram was even removed from Play Store for a few hours at the request of a South Korean competitor. For whatever reason, somebody in South Korea is seriously pissed off with Telegram. [1] https://twitter.com/durov/status/619486763032182784
Re: A DDoS in Asia Pacific
#34Earlier quoted context omitted.
What makes you think OVH could cope with a 200 Gbps DoS attack of this nature? A quick look at their services indicates they don't mention what kind of attacks they defend against, and SYN floods are some of the hardest to defend against.
They say they have facilities to clean 480Gbps of data, and 5Tbps of mostly spare inbound bandwidth, so their DDoS mitigation capacity is somewhere in that range ( http://www.ovh.com/ca/en/a1171.protection-anti-ddos-service-... ).
Re: A DDoS in Asia Pacific
#35Earlier quoted context omitted.
They say they have facilities to clean 480Gbps of data, and 5Tbps of mostly spare inbound bandwidth, so their DDoS mitigation capacity is somewhere in that range ( http://www.ovh.com/ca/en/a1171.protection-anti-ddos-service-... ).
480Gbps across all their datacenters. Each datacenter only has 160Gbps, and I doubt that they'll devote all of that to one client.
Re: A DDoS in Asia Pacific
#36Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).
Re: A DDoS in Asia Pacific
#37Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).
OVH frequently has problems with false positives, or so some of their customers report. They may offer good value for non-critical services, but they aren't exactly known for 100% uptime.
Re: A DDoS in Asia Pacific
#38Question: Is this possible because they are using Linux servers? The Linux kernel adopted TCP Fast Open? https://www.ietf.org/mail-archive/web/tcpm/current/msg08204....
We started blocking these large requests over 3 years ago when we started seeing them. Interestingly enough, that was a full 6-9 months before Radware wrote an article and coined the term Tsunami SYN. We just called it "big SYN". The attack is trivially easy to stop, and anyone running a client that tries a TCP Fast Open should expect failure frequently.
Re: A DDoS in Asia Pacific
#39Simple solution: move to OVH. Although they don't have servers in SE Asia, perhaps 100% uptime is more important than shaving 100ms off the ping time. (As far as I can tell they don't have real-time audio or video anyway).
What makes you think OVH could cope with a 200 Gbps DoS attack of this nature? A quick look at their services indicates they don't mention what kind of attacks they defend against, and SYN floods are some of the hardest to defend against.
Re: A DDoS in Asia Pacific
#40Earlier quoted context omitted.
What makes you think OVH could cope with a 200 Gbps DoS attack of this nature? A quick look at their services indicates they don't mention what kind of attacks they defend against, and SYN floods are some of the hardest to defend against.
They say they have facilities to clean 480Gbps of data, and 5Tbps of mostly spare inbound bandwidth, so their DDoS mitigation capacity is somewhere in that range ( http://www.ovh.com/ca/en/a1171.protection-anti-ddos-service-... ).