Jump to content

Recommended Posts

Posted (edited)

Hi We have been attacked by to networks 190.172.0.0/15 & 190.178.0.0/15. We have Smoothwall, and working with their helpdesk we have blocked the networks but still had no internet access due to the attack continuing. Our ISP is BT the have told me I need to purchase Ddos Mitigation services from them, and as a gesture they have setup an access rule blocking the two networks.

 

My question is is there an alternative to BT's service, have any of you experienced this and what did you do? I really thought that my Smoothwall box was all that I would need but apparently not.

 

Thanks

Edited by edie209
Posted
Is it a BT Leased Business line? I thought the service would have covered all of that...

 

It is and like you you I thought we were covered

Posted

How many external IP addresses do you have?

What we do when under DDOS is:

 

1) Change IP address

2) notice when students search for 'whats my IP' to find the new address.

3) Catch student

4) Inform police

 

If you keep changing between addresses the kids will mess up at some point and then you can catch them.

Posted
When we entered into the contract we took the top package available, but they are now saying we didn't purchase it, we have had many problems with BT Local Business, we are coming to the end of a 3 year contract and in that time we have had probably 6 maybe 7 account managers. I think we will be looking elsewhere next time but that doesn't sort the current problem.
Posted
@mjk is there any particular software you have seen them use?

 

There was a 'network stress' website that essentially did DDOS. I can't recall the site name but it took money in order to take out your network !

Posted

DDoS services are so cheap nowadays anyone can buy enough capacity to take out a school's internet connection. No amount of software will help with that, you need to stop the problem either politically (catching whoever is organising it) or by working with your upstream provider (i.e. BT) who can blackhole the traffic or put you through a traffic scrubbing device like those Arbor make before that traffic ever hits your connection.

 

BT ought to do it, I can understand why they want you to pay $$$ (DDoS mitigation is *expensive*), next time I would make it a requirement on your RFQ when you look at changing suppliers.

Posted
You should have a lot of functionality to help prevent this in your FW. Your ISP should be blocking any fraudulent IP packets at their level but there are things you can do yourself like stopping the return address from being rewritten dropping icmp and rate limiting other well known attack protocols. DDoS attacks by nature are hard to pinpoint and are normally orchestrated by a large number of zombie clients without the actual owners knowledge so its hard to get help from the authorities.....
Posted

Do you have any incoming ports open? e.g. for RDP etc

Mitigating it isnt easy short of catching the pupil and preventing ip leakage after rotating your ip address but preventing leakage can be very hard without routing through an upstream proxy really (which adds a whole host of issues both technically and GDPR potentially)

Having a second connection for only staff to use would be a possible fall back if your main link gets attacked which would prevent pupils hopefully getting its ip but you would need to double check email sent externally isnt leaking your ip as well in the headers (it can be prevented on o365)

Posted

@gaz350b if that is still the price we have no chance of affording it :(

@HPlum78 BT are stating that blocking the IP's responsible is ddos mitigation and we have to pay for it, we are dropping icmp. I am not sure what you mean by "stopping the return address from being rewritten"

 

@ZeroHour We do have some incoming ports open RDP and Sims Teacher app. As to leaking my IP, is this what you are refering to https://practical365.com/exchange-server/remove-internal-exchange-server-names-ip-addresses-message-headers/

Posted
When we entered into the contract we took the top package available, but they are now saying we didn't purchase it, we have had many problems with BT Local Business, we are coming to the end of a 3 year contract and in that time we have had probably 6 maybe 7 account managers. I think we will be looking elsewhere next time but that doesn't sort the current problem.
I will rather chew both my arms and legs off risking infection rather than having to deal with our BT local business again. This will be our second spell with a BT leased line, and whilst the line hasn't gone down once in 3 years (touch wood) dealing with them has been painful and so time consuming, it makes you consider moving elsewhere, just to avoid the pain.

 

but the line is great :)

Posted

DDOS mitigation can only really happen upstream from your own router - if the traffic is hitting your edge, then blocking it won't do anything to alleviate the bandwidth it is using.

 

So, you're at the mercy of your ISP for it.

Posted

@localzuk is right here.

 

it doesn't matter how good the DDoS protection is with an onsite firewall if you're line can only take so 100Mbit and a DDoS is sending say 2Gbit of traffic to it.

 

ISPs can do multiple things to mitigate DDoS attacks. We do quite a bit which his FOC and as our firewalls are hosted rather than onsite then the DDoS effectively gets blocked in our network rather than onsite so won't saturate your line.

 

There are paid for services such as DDoS scrubbing which is a useful tool but is something you should pay for as ISP's do. It basically allows you to move your real world IP's from the ISP network to a VERY big network that has a dedicated anti DDoS network which will filter bad traffic and send on good traffic. Whilst the DDoS is still occurring you can then try find out why it's happening without your leased lines / network melting.

 

The above is just for a volumetric attack of course. There are plenty of other types of DDoS which can target specific applications which can send router or server CPU's to max out. WAFs (Web application firewalls) are normally best for this if you've a device which is Internet facing rather than a LAN behind a normal firewall which is just running NAT.

 

Have BT told you what type of DDoS you are experiencing? Can you get any logs from your smoothwall box to show what type of attack it is?

 

DNS reflection is a common DDoS which BT may still be able to help you with without special anti-DDoS provision. See https://www.incapsula.com/ddos/attack-glossary/dns-amplification.html for an overview.

 

Good luck

 

Dave

Posted

How did you know you were being DDOSed by those IPs? What sort of traffic/attack was it?

 

You can probably alleviate the issue a bit by closing off any inbound ports that are opened unnecessarily. This won't help the actual DDOS but the attacker might give up with the attack if you've closed down whatever they are trying to hit.

 

For example, if you've got RDP and websites available to the internet, you could switch them off for a day or so and see if the attack goes away.

 

What is your bandwidth? If your pipe is big enough (say 100Mbps+) then whether you have paid for DDOS mitigation or not ISPs will generally start applying their own mitigation because it is in their interest to stop large quantities of data coming into their network only to be discarded at the customer site, which is why it seems unusual to me that you are being so badly affected. Could it actually be that one of your internet facing services is being attaked (a webpage etc) which is what is actually causing the main issues?

Posted
Next time you are looking at buying a line then speak to Jisc as they are considerably cheaper than most providers and have DDoS mitigation built in even at that price.
Posted
Next time you are looking at buying a line then speak to Jisc as they are considerably cheaper than most providers and have DDoS mitigation built in even at that price.

 

I may be wrong (and I'm really not trying to attack a competitor here) but didn't Jisc / Janet have many long outages due to DDoS attacks against its network in the last 12 months?

 

Dave

Posted
Yes they did have an outage around a couple of years ago (Not aware of one in the last 12 months). However their new free DDoS mitigation offers are far better then a lot of providers out there without naming any companies.
Posted

Has anyone thought about routing their services through CloudFlare? They have DDoS protection built in, we have a good number of DNS entries setup with them some go through CloudFlare and others to bypass.

 

Check it out as it certainly cheaper than most.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...