Degraded performance on DDoS Protection

Incident Report for dataforest

Resolved

The root cause could be found and solved. No further impact was observed over the week.
Posted Oct 27, 2024 - 13:36 CET

Update

Further attacks of 1-2 Tbit/s have hit our network today, our rules have filtered them out completely, so the network is _not_ currently affected by an acute problem or performance problems. As the filters on our carrier aggregation switches are not yet working properly, we are leaving the incident open.
Posted Oct 22, 2024 - 03:56 CEST

Monitoring

We monitor the situation after we have set appropriate filters. These filters have already been set due to one of the last incidents, we have to check why they did not work as expected, according to the current state of knowledge we have to assume that it is a software bug from Juniper. As already mentioned, we have sufficient bandwidth to our various carriers to filter even large DDoS attacks with well over 2 TBit/s without any problems.
Posted Oct 21, 2024 - 03:02 CEST

Update

We are continuing to work on a fix for this issue.
Posted Oct 20, 2024 - 19:14 CEST

Identified

Initial countermeasures were taken as part of the filtering process so that the latest attacks no longer had any impact. We are still working on a permanent solution.
Posted Oct 20, 2024 - 19:05 CEST

Investigating

According to https://status.dataforest.net/incidents/zdmn6p79g58n we see the same attack, with adapted attack vectors and implement appropriate mitigation measures.
Posted Oct 20, 2024 - 18:54 CEST
This incident affected: [dataforest Backbone] Interxion FRA8 (DDoS Protection (affects all locations)).