Forum Discussion
iRule for DNS Flood protection
- Oct 06, 2016
You can apply a similar logic
https://devcentral.f5.com/codeshare/http-request-throttle-version-101-and-above
Not sure I get the context.
Most DNS DDoS attacks are reflected, so you receive answers, not questions.
I cynically suspect well configured DNS server will handle floods of requests faster than F5 iRules, I know back in the days of 486 PCs we you could saturate the wire (only 100Mbps back then) before you got performance issues with DNS servers.
There are also cheap/free suppliers of authoritative DNS services with AnyCast and other DDoS protections.
You are seeing floods of queries, but not for your own domains? If it is malicious they'll switch to using your domains.
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com