Re: syn flood attacks from NL-based netblocks

2019-08-20 Thread Florian Brandstetter
​​Load balancing is done on Layer 4 or Layer 3 when routing, so your ingress connection will have the same hash as the outgoing connection (unless the source port of the connection changes on the ACK - which it really should not). On Mon, 08/19/2019 06:18 PM, Töma Gavrichenkov wrote: > On Mon

Re: syn flood attacks from NL-based netblocks

2019-08-20 Thread Jakob Heitz (jheitz) via NANOG
The source address in the SYN is spoofed. What if the real owner of the source address wanted to connect to you? Then your penaltybox would block him. An attacker could now use your penaltybox to cause a DoS to the real owner of the IP address. > Date: Sun, 18 Aug 2019 08:48:08 -0700 > From: Mi