Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Recent DNS issues - NTL speaks....

You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Virgin Media Services > Virgin Media Internet Service

Recent DNS issues - NTL speaks....
Reply
 
Thread Tools
Old 10-06-2006, 17:36   #16
Paul
Dr Pepper Addict
Cable Forum Admin
 
Paul's Avatar
 
Join Date: Oct 2003
Location: Nottingham
Age: 63
Services: IDNet FTTP (1000M), Sky Q TV, Sky Mobile, Flextel SIP
Posts: 30,309
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Paul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered starsPaul is seeing silvered stars
Re: Recent DNS issues - NTL speaks....

Without information on the nature of the ddos attacks it's impossible to say if anything could be done. Some attacks are just impossible to stop and you have to ride them out.
__________________

Baby, I was born this way.
Paul is offline   Reply With Quote
Advertisement
Old 10-06-2006, 18:28   #17
Chrysalis
Inactive
 
Join Date: Sep 2003
Posts: 12,047
Chrysalis is cast in bronzeChrysalis is cast in bronzeChrysalis is cast in bronzeChrysalis is cast in bronze
Chrysalis is cast in bronze
Re: Recent DNS issues - NTL speaks....

if some small isp with 100mbit of peering I could understand but ntl have many gigabits of peering so they probably cant be taken down with a bandwidth saturation attack so I can only assume they either let the traffic reach the dns servers unfiltered. Or it was a simple request overload on the servers (resource consumption).

A isp of ntl's size should be able to mitigate a ddos attack, their are a few ways to do it but the first step would be buying some high end juniper hardware configuring it to filter attacks before they even reach the dns servers and then add more dns servers so their is some better redundancy.

Of course if they not willing to spend money, what they can do is much more limited.
Chrysalis is offline   Reply With Quote
Old 10-06-2006, 18:42   #18
HowardCanning
Inactive
 
Join Date: Mar 2005
Location: nr. Addlestone, Surrey
Services: 50MB internet, V+ box etc
Posts: 99
HowardCanning is an unknown quantity at this point
Re: Recent DNS issues - NTL speaks....

This is ridiculous, I can barely browse... Are there any other working DNS addresses we can use in the interim?
HowardCanning is offline   Reply With Quote
Old 10-06-2006, 21:00   #19
James Henry
Permanently Banned
 
James Henry's Avatar
 
Join Date: Apr 2006
Posts: 562
James Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these partsJames Henry is just so famous around these parts
Re: Recent DNS issues - NTL speaks....

Quote:
Originally Posted by Paul M
Without information on the nature of the ddos attacks it's impossible to say if anything could be done. Some attacks are just impossible to stop and you have to ride them out.
There is no such thing as an unstoppable attack apart from those that rely on raw bandwidth and even those can be prevented by a distributed server architecture. It is impossible to simulate normal traffic to the extent where it is able to take a well specified server down.

The fact is ntl don't have the technology in place to repel these attacks, and are I suspect just throwing more server capacity at it. That was what was happening previously anyway.

There are plenty of manufacturers offering DDoS mitigation hardware. These attacks I seriously doubt are anything more than SYN or UDP floods. Attacking DNS through repeated querying can be blocked upstream as well. It's all a case of having the layer 7 inspection and filtering in place to allow the legitimate traffic through while blocking the bad stuff.

NTL might do well to have a chat with someone selling http://www.toplayer.com/ equipment.

A look at http://www.google.com/search?q=DDoS+mitigation shows a number of options too.

There's a difference between being unable to stop the attacks and regarding them as an 'acceptable risk' and choosing not to invest the required sums to stop them.

You do wonder why these servers are even reachable from the outside. The servers the customers query could be seperated from the servers which other DNS servers query.

Personally I'd be all in favour of regional DNS servers, at the moment there's a distributed (and unnecessary) caching architecture, but the DNS is centralised still, which makes no sense apart from the financial one.

Either way this is inexcusable, and I wouldn't blame the engineers for this, I'd blame the people holding the purse strings and the people demanding wading through red tape before getting at the purse.
James Henry is offline   Reply With Quote
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +1. The time now is 13:29.


Server: osmium.zmnt.uk
Powered by vBulletin® Version 3.8.11
Copyright ©2000 - 2026, vBulletin Solutions Inc.
All Posts and Content are © Cable Forum