dns amplification attack

Reply
Highlighted
L4 Transporter

dns amplification attack

Hi,

 

What are the best practices need to be followed  to  protect from the ddos  dns amplification attack . 

How to  filter the  trace  from the  log  if there is any attack happened ? 

Thanks


Accepted Solutions
Highlighted
L6 Presenter

Highlighted
L5 Sessionator

Zone protection profile on outside/internet interface will protect your servers from traffic originating from internet.

Zone protection profile on interface where your DNS servers are will prevent your servers sending a lot of traffic towards internet (or some other zone) if they get compromised somehow. 

View solution in original post


All Replies
L5 Sessionator

Zone protection on outside/external/internet interface to protect your servers. And zone protection on the interface where your DNS servers are to prevent your servers being used as amplifiers. 

Highlighted
L6 Presenter

Highlighted
L4 Transporter

Hi,

"And zone protection on the interface where your DNS servers are to prevent your servers being used as amplifiers. "

Can you explain how to do that .

Thank you 

Highlighted
L5 Sessionator

Zone protection profile on outside/internet interface will protect your servers from traffic originating from internet.

Zone protection profile on interface where your DNS servers are will prevent your servers sending a lot of traffic towards internet (or some other zone) if they get compromised somehow. 

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the Live Community as a whole!

The Live Community thanks you for your participation!