Community discussions

MikroTik App
 
parvedejs
just joined
Topic Author
Posts: 2
Joined: Thu Jul 01, 2010 11:24 am

DNS DDOS amplification attack (FW rule)

Wed Jul 10, 2013 11:58 am

Hi
I have a network with servers which are not correctly configured, and time to time are used for this kind of attack, unfortunately I do not have access to configure them correctly. I have only Mikrotik router which I able to configure , in the middle , between internet and this servers .

Idea:
make FW rule which compare incoming and outgoing traffic per session for UDP port 53 connection , and if outgoing amount of data in 1.5 bigger then incoming , place source address in drop list.

Question :
how to write this rule ?
 
User avatar
EMOziko
Member Candidate
Member Candidate
Posts: 129
Joined: Mon Aug 23, 2010 9:42 pm
Location: Georgia

Re: DNS DDOS amplification attack (FW rule)

Wed Jul 10, 2013 12:08 pm

It's very good idea. Cause just blocking DNS traffic from non-trusted interfaces, sometimes is not an option.

Who is online

Users browsing this forum: Bing [Bot] and 88 guests