Earlier quoted context omitted.
Best way to defend against an L7 DDoS is to have the origin hidden, and to cache everything at a large number of geographically distributed PoPs. This helps in 99% of cases, and where it doesn't it is simply because there is a resource that cannot be cached and that the edge must revisit the origin for. This is especially true whenever that resource is expensive for the origin to provide (involves database lookups an…
What's the limit at which CloudFlare will start billing you at a "enterprise rate" instead of $20 / month? That bandwidth can't be free forever...
AWS Best Practices for DDoS Resiliency [pdf]
41–47 of 47 posts
Re: AWS Best Practices for DDoS Resiliency [pdf]
#42Earlier quoted context omitted.
Sounds like there could be awesome features here. Remotely triggered black holes for VPC? Elastic Firewall? Not crazy about firewalls in general, but they would help in the case that you are paying for data-out.
Firewalls are useless in a DDOS attack.
Re: AWS Best Practices for DDoS Resiliency [pdf]
#43Earlier quoted context omitted.
CloudFlare has CNAME flattening so you can still have the apex point to a CNAME and CF will automatically keep up to date with the correct IP using the TTLs and broadcast an A record correct to RFC standards. https://support.cloudflare.com/hc/en-us/articles/200169056-C...
Do you know if CloudFlare's apex CNAME support works coupled to Route53's health-check-based RRDNS? I know that AWS's own DNS reflects the health-check-based changes to the round-robin pools instantaneously, but I have no idea what sort of TTLs they emit.
There's no way to ensure the rest of the internet will handle it correctly though with all the proxies and DNS caches in the middle and low TTLs can also add latency to end-users who might have to constantly do a DNS lookup on new connections.
If you're using CloudFlare's full service (instead of just DNS), then it'll be seamless because their IPs don't change.
[1] https://blog.cloudflare.com/introducing-cname-flattening-rfc...
Re: AWS Best Practices for DDoS Resiliency [pdf]
#44The AWS best practice for DDoS, TLDR: Use anything except AWS unless you like going bankrupt in a day.
Re: AWS Best Practices for DDoS Resiliency [pdf]
#45Earlier quoted context omitted.
Sounds like there could be awesome features here. Remotely triggered black holes for VPC? Elastic Firewall? Not crazy about firewalls in general, but they would help in the case that you are paying for data-out.
Firewalls are useless in a DDOS attack.
Re: AWS Best Practices for DDoS Resiliency [pdf]
#46Kind of agree with all those who say that Cloudflare is still a better option. But how do you tackle their lack of automatic failover ? https://support.cloudflare.com/hc/en-us/articles/200168916-C... "the system currently does not have the functionality to automatically select the next available server if one of the servers in the group goes down"
Re: AWS Best Practices for DDoS Resiliency [pdf]
#47AWS' competition like OVH and many quality VPS providers offer _free_ (or very cheap) DDOS protection.
Which VPS providers are you referring to? I know from personal experience that, Digital Ocean, the largest VPS provider null routes your VPS IP for 3 hours minimium for even the tiniest of DDoS's. I doubt most of the smaller VPS providers can afford to absorb DDoS's even if they don't have overly restrictive policies like DO.
buyvm.net for 3$ per month (100Gbit apparently)
iwstack.com, 8Gbit protection for free
ramnode.com, 20Gbit