Skip to Content.
Sympa Menu

rare-dev - Re: [rare-dev] Set up a scrubbing solution as reference design for DDOS with WEDGE100BF32X

Subject: Rare project developers

List archive

Re: [rare-dev] Set up a scrubbing solution as reference design for DDOS with WEDGE100BF32X


Chronological Thread 
  • From: mc36 <>
  • To: ,
  • Subject: Re: [rare-dev] Set up a scrubbing solution as reference design for DDOS with WEDGE100BF32X
  • Date: Thu, 24 Mar 2022 09:24:33 +0100

hi,
here are our onie installers: http://hydra.nix.net.switch.ch/RARE/releases/
i suggest you to wait a bit until the next ones arrive simply because that
one will have the profiles needed to do the scrubbing...
afterwards, you'll have the profiles under
https://bitbucket.software.geant.org/projects/RARE/repos/rare/browse/profiles/9.7.1
the things to look at is -fw and -cleaner...
the -fw one is a stateful firewall, that is, tofino will have the sessions
going through the box at it's speed,
and only the new flows will be handled in freerouter, and if it's allowed,
then propagated to the asic...
the -cleaner one is just a routing instance that one could instruct to do the
redirect/ratelimit via bgp flowspec...
until the tofino images will be ready, you can start experimenting with pure
freerouter to get familiar with things,
then i suggest you to play with the dpdk or libpcap dataplanes... they act
exactly the same as the asic based ones...
br,
cs


On 3/24/22 09:14, wrote:
Hi everybody,
i was going through ietf 113hackathon
wiki[https://trac.ietf.org/trac/ietf/meeting/wiki/113hackathon] today and saw
"Set up a scrubbing solution as reference design for DDOS with WEDGE100BF32X"
under
RARE/freeRtr/Project(s)
I did not attend to hackathon but congratulations to the champions attended to
hackathon.
So, this scrubbing topic got me interested on RARE/freeRtr even more and there
are 2 wedge100bf32x boxes around me to try the reference design out.
Saw old cleaner profile for p4 data plane in the list's archive but couldn't
determine if this is same setup with it..
Can anyone share notes/recordings about how should one set the box to test for
ddos scrubbing with flowspec or any rundocs if there's any?

Thanks,



Archive powered by MHonArc 2.6.19.

Top of Page