Hacker News new | ask | show | jobs
by iptrans 1225 days ago
I’m interested to hear how you

1) block 2 Tbps of attack traffic

2) save $500k per month in bandwidth charges since blocking at the border means you have to pay for the incoming bandwidth

3 comments

1. Not sure where you got 2tbps? I said 10gbps, but we use Alamai’s manages Prolexic ddos mitigation. At previous companies we would buy a half dozen of these, put them at different exchanges and buy transit from the biggest aggregators. This would cost about $4m to get started

2. I meant $50k per month, edited. This does not count loss of productivity.

Sound like you are probably just overpaying for bandwidth and/or DDoS protection.
Supposedly the traffic being blocked would have generated more outgoing traffic, costing more. Also, GP is managing their connections at the bgp level, meaning the requests don't ever hit their firewall, they just are unroutable from these countries ips.
BGP doesn’t work that way.

You cannot control who your prefix is announced to, unless you control all the paths on the Internet.

DDoS don't only cost bandwidth.
OP literally said 500k of bandwidth charges.
And the person you replied to said "only".