AS53427
DDoS Mitigation

Best practices DDoS

Operational recommendations to reduce the impact of attacks and improve incident response.

IPv6

Keep IPv6 fully operational across the network and services. A well-operated dual-stack architecture provides additional options during incidents and reduces unnecessary dependence on IPv4.

Detection

Use telemetry and detection tools to quickly identify the affected prefix, attack vector and attack volume.

BGP Communities

Know the blackhole, mitigation and traffic-engineering Communities in advance. These controls should be documented and ready for use before an incident occurs.

GRE, MTU and TCP MSS

When GRE encapsulation is used, validate MTU and TCP MSS to prevent fragmentation or silent packet loss.

Network resilience

Ensure sufficient capacity on edge routers, concentrators, CGNAT platforms, firewalls and internal links. Upstream mitigation does not eliminate bottlenecks within the customer network.

Periodic testing

Validate routes, Communities, tunnels, filters, automation and operational procedures before a real attack occurs.

Copied