Contents
How can IPsec help with DDoS attacks?
If a flooding DDoS attack occurs, organizations should limit IKE/ISAKMP traffic, only allowing traffic from known sites. As IPSec is primarily used to establish VPN connections between pre-defined sites, organizations can pre-define the IP addresses of those sites in Infrastructure Access Lists (iACL’s).
What is a fragmentation DDoS attack?
An Internet Protocol (IP)/Internet Control Message Protocol (ICMP) fragmentation DDoS attack is a common form of volumetric denial of service (DoS) attack. In such an attack, datagram fragmentation mechanisms are used to overwhelm the network. This process is necessary to meet size limits that each network can handle.
Which protocol uses fragmentation attacks?
UDP (Used Datagram Protocol) and ICMP (Internet Control Message Protocol) fragmentation attacks. In these attacks, servers are flooded with oversized or otherwise corrupt packets that they must reject. This can quickly overload a server’s resources and prevent it from performing its intended operations.
What attacks does IPsec protect against?
IPsec provides some protection against denial of service attacks but also creates some new holes. IPsec ESP/AH authentication provides strong protection against DoS because any spoofed packets will be identified and discarded.
Why is an IPsec flood DDoS attack dangerous?
Any DDoS attack is dangerous because the intention of the attack is to overwhelm system resources. When an IPSec flood attack is successful, it causes the impacted system to exhaust all available resources, preventing it from servicing legitimate requests, and resulting in traffic traversing IPSec VPN connections being affected.
What to do in case of flooding DDoS attack?
If a flooding DDoS attack occurs, organizations should limit IKE/ISAKMP traffic, only allowing traffic from known sites. As IPSec is primarily used to establish VPN connections between pre-defined sites, organizations can pre-define the IP addresses of those sites in Infrastructure Access Lists (iACL’s).
What can IPsec be used for in a VPN?
As IPSec is primarily used to establish VPN connections between pre-defined sites, organizations can pre-define the IP addresses of those sites in Infrastructure Access Lists (iACL’s). Additional steps that can be taken include: