Community discussions

MikroTik App
 
wurstel
just joined
Topic Author
Posts: 23
Joined: Thu Apr 13, 2017 7:04 pm

use server xeon like bgp router

Tue Sep 26, 2017 10:31 am

Hi,
i would like to changemy bgp router ccr1072 with a xeon server because when i have ddos attack cpu go to 100% and I loss packets.
there is a pci that mikrotik support for have at least 4x 10G ports?
thank you
 
User avatar
gamerxp
just joined
Posts: 10
Joined: Fri Dec 09, 2016 2:54 am
Location: Thailand
Contact:

Re: use server xeon like bgp router

Wed Nov 29, 2017 7:15 am

Hi

I have pretty much same problem with you before but I have found out that when you drop attack traffic with IP > Firewall > Raw CPU will come down and not having loss.
And I have use x86 RouterOS on Xeon E3 with Intel X520 before and still have problem when under attack.

Software router with small packets (especially attack traffic) are not going well. My advice is getting wire speed L3 switch with BGP. or Try use dst-limit to limit pps per IP.
 
User avatar
StubArea51
Trainer
Trainer
Posts: 1742
Joined: Fri Aug 10, 2012 6:46 am
Location: stubarea51.net
Contact:

Re: use server xeon like bgp router

Wed Dec 06, 2017 6:32 pm

I would consider a packet scrubber in between the upstream peer and the border router. This is what they are designed for.

We've used these successfully with both CCRs and CHRs to defend against DDoS attacks and use RTBH

http://www.serveru.us/en/