On 15 Apr 2016, at 4:35, Satish Patel wrote:

We thought about ASR firewall too but not sure because it can
handle DDoS or not.

Stateful firewalls aren't good at dealing with DDoS attacks - they go down more quickly that 'naked' hosts due to state-table exhaustion (link to .pdf preso):


S/RTBH, flowspec, and possibly intelligent DDoS mitigation systems (IDMSes) are tools you can utilize to deal with DDoS attacks.

[Full disclosure:  I work for a vendor of such systems.]

You also need to ensure that you implement BCPs like iACLs in order to ensure that your network infrastructure devices themselves are protected against DDoS attacks.

This is an older post on NANOG, but it still has relevance, IMHO:


Again, be sure to include flowspec (supported on Juniper platforms for a long time, now finally supported on some Cisco platforms) in your toolkit.

There are other .pdf presos related to DDoS defense which may be of interest here:


Roland Dobbins <rdobb...@arbor.net>
juniper-nsp mailing list juniper-nsp@puck.nether.net

Reply via email to