下载PDF
NETSCOUT > 实例探究 > Transition from Cisco Guard to the Peakflow Solution Provides Easier 10 Gbps DDoS Attack Mitigation
NETSCOUT Logo

Transition from Cisco Guard to the Peakflow Solution Provides Easier 10 Gbps DDoS Attack Mitigation

技术
  • 网络安全和隐私 - 网络安全
适用行业
  • 教育
适用功能
  • 商业运营
用例
  • 网络安全
服务
  • 系统集成
挑战
The customer, a central European network service provider (NSP) that offers Internet access, domain name system (DNS), IP address allocation and DDoS attack detection and mitigation services to universities, ministries and research organizations, was using Cisco Guard for DDoS attack detection and mitigation. However, they faced two main problems with Cisco Guard. Firstly, the NSP had a 10 Gbps core backbone network, but Cisco Guard only supported 1.2 Gbps of mitigation, and there were no plans to improve this due to the end-of-sale schedule. Secondly, because the NSP used Peakflow SP for attack detection and Cisco Guard for attack mitigation, its staff was forced to learn two different user interfaces, which made attack mitigation more difficult.
关于客户
The customer is a central European network service provider (NSP) that offers Internet access, domain name system (DNS), IP address allocation and DDoS attack detection and mitigation services to universities, ministries and research organizations. Its network, consisting mainly of Cisco devices, supports about 150 customers with thousands of end users. Three core routers, connected via a 10 Gbps fiber backbone, provide all the routing to neighboring countries, research networks and commercial upstream providers.
解决方案
The NSP transitioned from Cisco Guard to Peakflow SP TMS. The migration process was relatively easy, with minor changes required to the network routing environment. Since Peakflow SP TMS is an out-of-band appliance that doesn’t do any active routing, the NSP had to implement a separate routing instance to segregate the production Border Gateway Protocol (BGP) forwarding routing tables from the individual scrubbing routing tables. This routing instance was used for off-ramping attack traffic to the TMS appliance. TMS would then on-ramp or forward cleaned traffic into this routing instance, where the routers would make next-hop decisions for Peakflow SP TMS to deliver clean traffic to its original destination.
运营影响
  • The NSP can now protect its whole 10 Gbps core backbone with a single 10 Gbps mitigation device (the TMS 3100).
  • The team only needs to learn one solution, simplifying the process and reducing the time required for training.
  • It now only takes 4 or 5 clicks to start a mitigation, providing a very simple and fast way to stop attacks within 10 to 15 seconds.
数量效益
  • 10 Gbps DDoS attack mitigation capability
  • Attack mitigation can be started within 10 to 15 seconds

相关案例.

联系我们

欢迎与我们交流!

* Required
* Required
* Required
* Invalid email address
提交此表单,即表示您同意 IoT ONE 可以与您联系并分享洞察和营销信息。
不,谢谢,我不想收到来自 IoT ONE 的任何营销电子邮件。
提交

Thank you for your message!
We will contact you soon.