[c-nsp] DDOS, router acted oddly.

2007-08-30 Thread Drew Weaver
I believe I know why I had the issue I had last evening when a 500Mbps DDOS hit our network. I believe it is due to queuing issues, but I am not sure, I wanted to ask you folks what you thought. The topology of the 'attack ' is as such: Attacker - Internet - 3Gbps aggregate(4

Re: [c-nsp] DDOS, router acted oddly.

2007-08-30 Thread Drew Weaver
9:52 AM To: cisco-nsp@puck.nether.net Subject: [c-nsp] DDOS, router acted oddly. I believe I know why I had the issue I had last evening when a 500Mbps DDOS hit our network. I believe it is due to queuing issues, but I am not sure, I wanted to ask you folks what you thought

Re: [c-nsp] DDOS, router acted oddly.

2007-08-30 Thread Oliver Boehmer \(oboehmer\)
Drew, a possible cause could be buffer shortage on the linecard. Unless you limit the queue length on the GSR interfaces, the linecard could allocate all available buffers (and there are plenty) when one of the links becomes congested, which could have happened if one of the GE links needed to

Re: [c-nsp] DDOS, router acted oddly.

2007-08-30 Thread mack
Message: 3 Date: Thu, 30 Aug 2007 10:32:05 -0400 From: Drew Weaver [EMAIL PROTECTED] Subject: Re: [c-nsp] DDOS, router acted oddly. To: cisco-nsp@puck.nether.net cisco-nsp@puck.nether.net Message-ID: [EMAIL PROTECTED] Content-Type: text/plain; charset=us-ascii More information