|
|
|
|
|
by imbriaco
4476 days ago
|
|
It's just the most efficient and visible way for us to do it, it's not the only way. Here's a couple of reasons why we like it: 1. It's scripted so you don't have to think about it at 3am. 2. The rest of the team can see it happening in realtime so you don't have to explain what you're doing via a side channel. They can see it happening. 3. It doesn't require specialized knowledge of routing to enable it. If the on-call engineer sees an attack and calls someone for guidance, it's super easy to tell them "type /mitigation enable" for instance. 4. Of course we can run the exact same script or login to our routers and manually change our BGP announcements if we need to. |
|