North American Network Operators Group|
Date Prev | Date Next | Date Index | Thread Index | Author Index | Historical
DOS attack assistance?
One of my customers, a host at 18.104.22.168, is feeling a "bonus" ~130kpps from 22.214.171.124. I've null-routed the source, though our Engine2 GE cards don't seem to be doing a proper job of that, unfortunately. The attack is a solid 300% more pps than our aggregate traffic levels.
It's coming in via 6461, but they don't appear to have any ability to backtrack it. Their only offer is to blackhole the destination until the attack subsides. BGP tells me the source is in AS 12322, a RIPE AS that has little if any information publicly visible.
Any pointers on what to do next?