DOS approach

hello i have been reading the ddos info on the mikrotik wiki site, is this wiki safe i wonder.

what is you dos security approach?

http://wiki.mikrotik.com/wiki/DoS_attack_protection

This is my view on the wiki approach - http://forum.mikrotik.com/t/ddos-story-or-warning-use-conection-limit-with-caution/49743/87
This is my approach - http://forum.mikrotik.com/t/why-source-based-blackhole-instead-of-firewall-drop/103496/1

Nice whats the latest on this blackhole method?

Do u preroute and mark packets before the firewall for this method??

@cloudflare

I just came across cloudflare they specialise in blocking 600gbps ddos looks like a good service how can i apply something like this to my mikrotik

Cloudflare is a cloud service, not one device. A router can’t take 600Gbit attack traffic and keep working normally. Your ISP uplink will be full, for one.

Yep i was just reading into layer 3 layer 4 and layer 7 ddos

Cloud based seems the best current option as it can implement multiple processing paths

Looking at options and how it works so i can build my understanding.

I see fortinet have a promising ddos hardware box

I wonder what it takes and what is involved maybe its possible for us to make one for mikrotik

Im now learning about bgp and gre tunnels any further info would be much appreciated