North American Network Operators Group

Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical

Re: Lazy network operators

  • From: Niels Bakker
  • Date: Fri Apr 16 12:46:57 2004

>> On the other hand, we've had DDoS prevention mechanisms (based on
>> multiple rate-limiters, for different kinds of packets) deployed for
>> over 6 months now.  They seem to work just fine, are always active,
>> and require no state in the network.

* [email protected] (Paul Vixie) [Fri 16 Apr 2004, 17:14 CEST]:
> you know how to rate-limit without state in the network?  please explain.

Unlike PNAT, you don't need to look at packets traveling both ways.
This is a plus, I suppose.


	-- Niels.