DDOS, this attack is the most harmful. The principle is to send a large number of data packets to the target server, occupying its bandwidth. For example, two cars can drive side by side on the road to your home, and I will get thousands of cars to drive on your road. Can the normal traffic in your home still go on? Many webmasters say that adding a firewall can really filter out most of the attack packets, not to mention how many firewalls are needed, so where should the firewall be added? I drew a sketch, which is not pretty, but it should explain the problem. If it is added between AB, the bandwidth above the firewall is 10M m, and the bandwidth has been used up when the firewall is hit. Adding a firewall will not help. Then if it is added between the 6502 switch and the cabinet switch, it can theoretically resist the traffic attack below 100M, but considering that the normal external service of the machine occupies a part of bandwidth, the actual defense cannot reach 100 m.
If you only host one machine, the access provider will not allow you to add a firewall on the upper level of the cabinet. If the attack traffic reaches g or more, it is necessary to add a firewall on the central switch, which depends on the bandwidth of the access center switch. Several small computer rooms in Shenzhen, such as Tianxin Nanshan Hongbo, have very small bandwidth, generally only one or two G's, and such computer rooms simply cannot withstand the attack of bandwidth above G's. One of my machines was attacked by 50G traffic, and it was useless for the city telecom to shield Ip, which affected the whole computer room. Later, it was the backbone of the provincial telecom that blocked the IP to make the computer room work normally. Having said that, I just want to make it clear that if it is a traffic attack, it is useless to simply add a firewall, and there must be enough bandwidth to cooperate with the firewall defense. The general market price is about 80,000 yuan for 2G firewall and 200,000 yuan for 4G firewall. If you want to defend against 10G traffic attack, you must use about 20G hardware firewall and nearly 20G bandwidth resources, so you need five 4G hard defenses for cluster protection, which is quite expensive. At present, there are special attack groups in China, such as knight attack group. By purchasing the bandwidth of broilers and some computer rooms, it is easy to generate more than 10G attack traffic. I used to protect a website, but I was attacked by 10. More than G traffic. Basically, no computer room is willing to receive such traffic. The attack lasted seven days and seven nights. We use CDN to distribute websites on different node servers and take turns to be on duty for 7 days and 7 nights. Of course, such protection is very expensive. The general protection fee is more than 10 thousand a day