This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

DDoS response plan

Hello.

I have a requirement to produce a DDoS response plan, and was wondering if anybody here had already done something similar and wouldn't mind sharing some tips or pointers on what they have included?  Such as how you monitor for DDoS attacks, how do you identify an attack, and what do you do to mitigate them?

We have a pair of SG230 appliances with TCP SYN Flood Protection, UDP Flood Protection and ICMP Flood Protection enabled.  What else can we do, or should we turn to our ISP for upstream detection and protection?

Thanks in advance for any tips!



This thread was automatically locked due to age.
  • I'm interested also, other than putting all DNS in triple redundant carriers all with DDOS protection, then the UTM will have less attacking at least for DNS.  I'll watch for someone to answer also, THank you

  • Hi guys,

    In a private exchange with Lucar Toni, he confirmed what I suspected - your ISP would need to provide this service.

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA