Skip to content

Poll: what's your actual DDoS filtering setup?

Networking by adam20 23 replies 3.3K views
#21

I used to run on-prem appliance. A10 Thunder. Bought it used for cheap, ran it two years, sold it for more. The hardware was fine but the licensing was a nightmare. Every feature was a separate subscription. "Oh you want SSL inspection? That is another $4K/year." Never again.

#22
marchhopper said:
Considering Anycast but that is another layer of complexity and another bill.

Anycast is great until it is not. I know a guy who ran his own anycast on three Vultr locations. Worked fine until Vultr had a routing issue in Amsterdam and 40% of his European traffic got blackholed. The "automatic" failover became automatic fail. You still need monitoring and manual override.

#23

ARM Ampere at Oracle Cloud Seoul. Their DDoS protection is included and actually decent for the price. I run upstream scrubbing there plus a small on-prem filter on a local dedicated line for latency-sensitive stuff. The Oracle layer handles volumetric. The local box handles application nonsense. Best of both if you can afford the hardware.

one small ping for man...
4 #24

I am reading this and I do not understand most of it. I run two WordPress sites on a shared host. Is that upstream scrubbing? Should I be doing something else? They have never gone down that I know of.

frames, tables, still valid HTML

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft