17.08.2016

BGP FLOW SPEC

All this docs about ExaBGP 4.0 (Git master branch)

Clone code:

They are not compatible with ExaBGP 3.0

Create file /root/announcer.py with your favorite editor:

Please be careful about flush and trailing ‘\n’!!!

Then edit fileĀ /etc/exabgp_flowspec.conf:

Run ExaBGP:

Then, you could run FastNetMon (since 1.1.3) with following options:

Be aware! We will announce rules with discard option!

Currently we support only most popular amplification attack types:

  • DNS amplification (we drop all udp traffic originating from 53 port
  • NTP amplification (we drop all udp traffic originating from 123 port)
  • SSDP amplification (we drop all udp traffic originating from 1900 port)
  • SNMP amplification (we drop all udp traffic originating from 161 port)