23 okt. 2023 10:00 schreef Andreas Danzer via Pdns-users
mailto:pdns-users@mailman.powerdns.com>>:
Hello Steffan,
that kind of attack is quite common these days. I would recommend
putting your authoriative nameservers behind dnsdist. Dnsdist acts as a
DNS firewall, pro
Hello Steffan,
that kind of attack is quite common these days. I would recommend
putting your authoriative nameservers behind dnsdist. Dnsdist acts as a
DNS firewall, proxy and loadbalancer.
We're running some rulesets on dnsdist, that e.g. dynamically block IPs
that "produce" unusual high n