全球主机交流论坛

标题: HE FMTII 核心路由器被D,已经接近3个小时了。 [打印本页]

作者: howie    时间: 2011-6-24 02:37
标题: HE FMTII 核心路由器被D,已经接近3个小时了。
哪个MJJ吃饱了撑着。。。
作者: domin    时间: 2011-6-24 02:39
据说好几天了已经

http://www.webhostingtalk.com/showthread.php?t=1058700
作者: howie    时间: 2011-6-24 02:42
怪不得,最近几天老是有线路中断警告,不过几分钟也就算了,今天也太离谱了。
作者: 我累了    时间: 2011-6-24 02:57

作者: nuet    时间: 2011-6-24 03:06
挂了几天了 郁闷啊
作者: fw5000    时间: 2011-6-24 03:09

作者: howie    时间: 2011-6-24 03:36
妈的那些鸟人可能50%的客户都是中国人,背后就在骂中国人。
作者: yrdesign    时间: 2011-6-24 04:44
提示: 作者被禁止或删除 内容自动屏蔽
作者: 退休老军医    时间: 2011-6-24 07:47
he 最近被日的很厉害
作者: cnx    时间: 2011-6-24 07:50
标题: 回复 5# nuet 的帖子
头像不错。
作者: zyzit    时间: 2011-6-24 07:52

作者: howie    时间: 2011-6-24 08:00
Incident: Performance degradation due to DDOS on June 23rd

On June 23, 2011 starting at approximately 9:00a PST, the
Fremont 2 datacenter was subject to of a large sustained
DDOS targeting a customer.  The attack caused OSPF and
BGP reloads resulting in elevated CPU utilization and
performance degradation on the router.  The offending
customer was identified and was moved to a different
router. The attack was partially mitigated at
approximately 11:00a PST, and full containment was realized
at approximately 11:30a PST.  We are working with the
vendor regarding these attacks and hope to have a more
robust solution in place should we see a reoccurrence.

Hurricane Electric makes every effort possible to minimize
the impact of router hardware and software upgrades, we
apologize for the inconvenience.

Hurricane Electric Customer Care
+1.510.580.4120

Hurricane Electric Operations
+1.510.580.4100

This notification is intended for the addressee only. The
material may be privileged and may contain confidential
information. If you have received this notification in
error, please notify Hurricane Electric immediately via
email and delete the original.

[ 本帖最后由 howie 于 2011-6-24 08:07 编辑 ]
作者: howie    时间: 2011-6-24 08:06
大致意思是美国太平洋时间9点左右,机房有个客人的设备被攻击,导致OSPF和BGP会话不断重载,占用了大量的CPU资源,降低路由器的性能。然后11点的时候,攻击流量有部分被转移到另外一个路由器上,11点半才完整转移所有攻击流量。

听说他们是是用了Broadcade / Foundry的设备,对D的处理机制不太好。我之前也想买个BigIron的核心交换机做BGP但是很多人说不好,小小攻击CPU就100%了,根本无法进去操作。
另外觉得奇怪的是,这么大的攻击干嘛不直接做BGP黑洞?
作者: domin    时间: 2011-6-24 08:25
标题: 回复 13# howie 的帖子
可能攻击不是针对特定一个IP. WHT上说的是针对FMT2上随机几个IP.
作者: howie    时间: 2011-6-24 08:36
前几天有个帖子说在测试高防,打了16G的带宽? 该不会是在测试高防,然后HE的路由器受不了了。
作者: domin    时间: 2011-6-24 09:07
主要是他们核心路由对抗DDOS有BUG
还是用Cisco或者Juniper吧
Brocade唉...

[ 本帖最后由 domin 于 2011-6-24 09:09 编辑 ]
作者: zyzit    时间: 2011-6-24 09:09

作者: 有个就好    时间: 2011-6-24 10:11
默哀3分钟
作者: hkin    时间: 2011-6-24 10:24
又挂了!!!




欢迎光临 全球主机交流论坛 (https://lilynana.eu.org/) Powered by Discuz! X3.4