Best practices DDoS
Operational recommendations to reduce the impact of attacks and improve incident response.
IPv6
Keep IPv6 fully operational across the network and services. A well-operated dual-stack architecture provides additional options during incidents and reduces unnecessary dependence on IPv4.
Detection
Use telemetry and detection tools to quickly identify the affected prefix, attack vector and attack volume.
BGP Communities
Know the blackhole, mitigation and traffic-engineering Communities in advance. These controls should be documented and ready for use before an incident occurs.
GRE, MTU and TCP MSS
When GRE encapsulation is used, validate MTU and TCP MSS to prevent fragmentation or silent packet loss.
Network resilience
Ensure sufficient capacity on edge routers, concentrators, CGNAT platforms, firewalls and internal links. Upstream mitigation does not eliminate bottlenecks within the customer network.
Periodic testing
Validate routes, Communities, tunnels, filters, automation and operational procedures before a real attack occurs.