Last week my network href="https://serverfault.com/questions/411938/esxi-server-under-dos-attack-can-i-use-ssh-to-determine-where-from">was
hit by a DDoS attack which completely saturated our 100 MBps link to the
internet and pretty much shut down all the sites and services we
host.
I understand (from this experience as well
as other answers) that
I cannot handle a DDoS attack such as this on my end, because even if we drop the
packets they have still been sent over our link and are saturating our
connection.
However when this happened my ISP
was (strangely enough) unable to tell me where the attack was coming from. They said if
I could determine the source (E.G. via tcpdump
) I could give
them IP addresses to block. But things were so overloaded that running
tcpdump
was impossible. I just couldn't view the
output.
Nearly all our servers are
behind a pfSense router. How can I detect a DDoS attack using pfSense so I can tell my
ISP who to block? I don't want to block the attack myself, I just want to get alerts /
be able to view a list of IP addresses that are using way more bandwidth than
normal.
The pfSense router is running Snort, if
that can be used to assist in any way.
Comments
Post a Comment