North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

DDoS: CAR vs TCP-Intercept vs NetFlow

  • From: Rubens Kuhl Jr.
  • Date: Mon Feb 28 20:56:35 2000

Have anyone performed an evalution of rate-limiting SYN packets (CAR) versus
using TCP-Intercept ? What responds better to a DDoS attack (assume
SYN-flooding only) ? What uses more router resources ?

For better performance of CAR or TCP-Intercept, NetFlow switching (ip
route-cache flow) should also be used, besides CEF ?



Rubens Kuhl Jr.