Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


New Corero DDoS mitigation
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

New Corero DDoS mitigation

jmginerjmginer Member, Patron Provider
edited April 2023 in Providers

Hello, we are pleased to announce that we have integrated a new DDoS attack mitigation service based on Corero technology.

We have been using Voxility's DDoS attack mitigation service for over 8 years, but in this time the attacks have evolved and so have our customers' services. Unfortunately Voxility does not seem to have adapted, they are still very inefficient in blocking tunneled traffic such as VPN, GREs, etc... and other protocols such as SIP or the whole gamming sector.

For this reason last year we integrated Path.net mitigation, which works very well especially for the gammig sector, but we see that it has some limitations with some services that are not included in their filters.

So, in order to fill that gap we have integrated a Corero solution hosted in our location, relying on our Juniper core routing and the GTT network, we believe we have completed a very advanced protection barrier.

We will continue to maintain the Path.net service for the gamming sector and the rest of the attacks we hope to mitigate with the new Corero integration.

If you want to test it, you can use the IP of the looking glass which is permanently routed by the mitigation equipment: https://corero.lg.ginernet.com/

For IPs that do not have permanent mitigation, we use Fastnetmon as detection and re-routing methods. It takes a few seconds to initiate mitigation.

PS- If anybody knows a good stresser please PM me.
Thanks!

Comments

  • Good. how much does it cost? i hope not a leg and an arm.

  • stefemanstefeman Member
    edited April 2023

    @SillyGoose said:
    Good. how much does it cost? i hope not a leg and an arm.

    Depends. Used gear goes for 20k per 1U sized unit.

    If its BGP tunnel, it should be cheaper.

    So basically anywhere from 5k to 5M USD depending on capacity and if its on-premises or not and new gear or not.

  • @stefeman said:

    @SillyGoose said:
    Good. how much does it cost? i hope not a leg and an arm.

    Depends. Used gear goes for 20k per 1U sized unit.

    If its BGP tunnel, it should be cheaper.

    So basically anywhere from 5k to 500k USD depending on capacity and if its on-premises or not and new gear or not.

    what more can i expect from corero.

  • stefemanstefeman Member
    edited April 2023

    @SillyGoose said:

    @stefeman said:

    @SillyGoose said:
    Good. how much does it cost? i hope not a leg and an arm.

    Depends. Used gear goes for 20k per 1U sized unit.

    If its BGP tunnel, it should be cheaper.

    So basically anywhere from 5k to 500k USD depending on capacity and if its on-premises or not and new gear or not.

    what more can i expect from corero.

    You need big ports and you need to stack these: https://itprice.com/juniper-price-list/corero.html

    Then you also need to buy lisences, trade profiles or make those profiles yourself.

    Its not cheap but its very good system. You can combine it with BGP Flowspec system for even better result such as what @Clouvider is doing.

  • NeoonNeoon Community Contributor, Veteran

    @jmginer said: anybody knows a good stresser please PM me.
    Thanks!

    Join a Political irc channel, shitpost, get tested.
    Works every time.

    Thanked by 1tentor
  • stefemanstefeman Member
    edited April 2023

    @Neoon said:

    @jmginer said: anybody knows a good stresser please PM me.
    Thanks!

    Join a Political irc channel, shitpost, get tested.
    Works every time.

    The amount of kids that will try to sell him some crap will be insane.

    Imagine paying 200€ for some site that advertises 200 Gbps and actually sends 100 Mbps at best, and this provider sees it as successful mitigation xD.

    Don't support such businesses. They are all hijacked machines.

  • tentortentor Member, Patron Provider
    edited April 2023

    @jmginer said: PS- If anybody knows a good stresser please PM me.
    Thanks!

    The easiest way to get free yet powerful DDoS attacks is to host public dstat.

  • how about a Corero launch special offer? (discount on ddos protected ips)

  • jmginerjmginer Member, Patron Provider
    edited April 2023

    @JoeMerit said:
    how about a Corero launch special offer? (discount on ddos protected ips)

    Hello, any of our IPs are routed over Corero in case of DDoS attack.

    Here we have a very nice VPS for just 19.95 €/year
    https://lowendtalk.com/discussion/185444/19-95-year-vps-kvm-hosted-in-spain-1-gb-ram-10-gb-nvme-10-gbps-bgp-ddos-protected

    Now, if you need an "allways on" Corero IP, the price it's just 3€/month/IP
    You can select this IP in the order process.

  • Very unusual and interesting latency.

  • @jmginer said:

    @JoeMerit said:
    how about a Corero launch special offer? (discount on ddos protected ips)

    Hello, any of our IPs are routed over Corero in case of DDoS attack.

    Here we have a very nice VPS for just 19.95 €/year
    https://lowendtalk.com/discussion/185444/19-95-year-vps-kvm-hosted-in-spain-1-gb-ram-10-gb-nvme-10-gbps-bgp-ddos-protected

    Now, if you need an "allways on" Corero IP, the price it's just 3€/month/IP
    You can select this IP in the order process.

    I didn't realize that you would give some protection included in the price. That is pretty nice! Makes your offers even more valuable.

  • FatGrizzlyFatGrizzly Member, Host Rep

    @jmginer said: PS- If anybody knows a good stresser please PM me.

    I'm not sure if this falls under the rules of LET, but I'll PM you a community.

  • therawtheraw Member
    edited April 2023

    @stefeman said:

    @SillyGoose said:
    Good. how much does it cost? i hope not a leg and an arm.

    Depends. Used gear goes for 20k per 1U sized unit.

    If its BGP tunnel, it should be cheaper.

    So basically anywhere from 5k to 5M USD depending on capacity and if its on-premises or not and new gear or not.

    weird how a company that charges this much and has anti-ddos specialists is using securi to protect their main site or is it part of corero aswell

  • stefemanstefeman Member
    edited April 2023

    @theraw said:

    @stefeman said:

    @SillyGoose said:
    Good. how much does it cost? i hope not a leg and an arm.

    Depends. Used gear goes for 20k per 1U sized unit.

    If its BGP tunnel, it should be cheaper.

    So basically anywhere from 5k to 5M USD depending on capacity and if its on-premises or not and new gear or not.

    weird how a company that charges this much and has anti-ddos specialists is using securi to protect their main site or is it part of corero aswell

    Which company? Security staff is pretty normal at larger datacenters.

    Ahh, you mean the WAF. Probly due to the included CDN and certifications which Sucuri has.

    Sucuri probly uses Corero too at their locations, and Corero uses Sucuri because why re-invent the wheel?

    Sucuri = WAF/CDN provider
    Corero = Network gear provider.

    Other is software, other is hardware/firmware.

    Thanked by 1theraw
  • alt_alt_ Member

    Looks nice, congrats on shifting.

  • @jmginer Whats total capacity of network and limit of attack capacity before /32 goes to blackhole?

  • tentortentor Member, Patron Provider

    @Matix8981 said:
    @jmginer Whats total capacity of network and limit of attack capacity before /32 goes to blackhole?

    I am not related nor to Corero nor ginernet but I have tested UDP amplification attacks of up to 50gbps without blackhole.

  • NeoonNeoon Community Contributor, Veteran
    edited April 2023

    @Matix8981 said:
    @jmginer Whats total capacity of network and limit of attack capacity before /32 goes to blackhole?

    It turns out, if you publish exact numbers, people are doing free load testing for you.
    They wanna know if your claims actually hold.

    Might be an additional free option.
    However, there is no stop button right, if your network goes off the cliff, it goes.

  • GhtGht Member

    Corero doesnt work on gaming at all , but Path yes.

  • rm_rm_ IPv6 Advocate, Veteran

    IPv6 listed on the Corero LG website does not work.

    $ ping  2a03:c7c0:1:48::1
    PING 2a03:c7c0:1:48::1(2a03:c7c0:1:48::1) 56 data bytes
    From 2001:688:0:3:8::350 icmp_seq=1 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=5 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=9 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=13 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=17 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=21 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=25 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=29 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=33 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=37 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=41 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=45 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=49 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=53 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=57 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=61 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=65 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=69 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=73 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=76 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=80 Destination unreachable: Address unreachable
    From 2001:688:0:3:8::350 icmp_seq=84 Destination unreachable: Address unreachable
    ^C
    --- 2a03:c7c0:1:48::1 ping statistics ---
    87 packets transmitted, 0 received, +22 errors, 100% packet loss, time 87352ms
  • As a Ginernet customer, this is good news.

Sign In or Register to comment.