top | item 41399250

(no title)

arcza | 1 year ago

Due to firewall logs showing DNS amplification attack attempts

discuss

order

Dylan16807|1 year ago

Why go beyond blocking direct DNS access?

(Ideally you'd make then switch to TCP by truncating UDP responses to specific clients but that sounds like a hassle to set up so it's understandable to skip that.)

immibis|1 year ago

Everyone is attempting all attacks all the time from everywhere. Why not secure yourself so the attempts fail?

oneplane|1 year ago

At that point secure would be 'offline'... It's not like botnets, "unlocker" farms and P2P doesn't originate from residential netblocks all day long.

The idea of "I just want the legitimate traffic" is a simple one, but the implementation of the idea has very little to do with "I will just block the big bad cloud!".