Skip to content
Discussion options

You must be logged in to vote

Thanks for asking. What you see is DNS amplification attack in progress. These are sadly very common and there is nothing much you can do about them. The only mitigation is to have query rate limiting configured and keep regular watch on the DNS server dashboard to detect any new attack. Once you see a new attack and if it uses a specific domain and type, you can then use the Drop Requests app and add that domain name and type that must be dropped.

Blocking IP address is something that is not feasible since these IP addresses keep varying and are of the victims of the attack. So using the Drop Requests app is enough to mitigate these attacks. These go away after a few days or a couple of …

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@narduin
Comment options

@ShreyasZare
Comment options

Answer selected by narduin
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants