Hi all,
I recently got a client (Linux web server) who became a target to DDOS attacks. Actually, the IP address of his web server was getting huge amounts of traffic indicating that it is a torrent tracker.
I blocked China and some other countries but that worked for a while. We ended up using a CDN and blocked all incoming traffic except the CDN and now everything is calm.
If I allow all incoming traffic in the firewall then all hell breaks!
The question is how did this happen? How can an IP address become marked like that and what do you do? (changing the IP is a solution of course).
I recently got a client (Linux web server) who became a target to DDOS attacks. Actually, the IP address of his web server was getting huge amounts of traffic indicating that it is a torrent tracker.
I blocked China and some other countries but that worked for a while. We ended up using a CDN and blocked all incoming traffic except the CDN and now everything is calm.
If I allow all incoming traffic in the firewall then all hell breaks!
The question is how did this happen? How can an IP address become marked like that and what do you do? (changing the IP is a solution of course).