Forum Discussion
The Business value of IP Reflection in Silverline DDOS Protection
Does IP Reflection mean that you can hide for an attacker that you are protećted by a scrubbing center?
What would a traceroute reveal?
If he knows that he would probably change strategy - run heavy SSL-attack and by observing response times could guess whether or not the scrubbing center has the private key.
He could also try to look for the real IP adresses or generate randomized strings in get/post-requests to bypass the center.
- amolariCirrostratus
With Silverline DDOS, F5 scrubbing network do not have your private keys (that's for Silverline WAF). Layer7 attack are still to be mitigated by the customer. But there is a communication API between BIG-IP (by the customer) and the SOC which will enable blocking of source IPs performing those L7 attacks at the scrubbing network level.
- BillyPT_180210Nimbostratus
http://www.google.com/patents/US20140245421
double static-NAT. public <-> private at Scrubbing Center facing to Customer. private <-> public at Customer facing Scrubbing Center. due to same public IP between first and second translation, it could be seen as reflection
public <-> private <-> public same IP same IP
Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com