Help - Search - Members - Calendar
Full Version: Additional IPs to floodguard protection
The Planet Forums > Security > DoS & D-DoS Mitigation
AlexAT
Let I order 8 more IPs to my additional 5 (total 13).
And order 10 IPs floodguard protection.

What should I do to be not charged for $250 per DOS incident when somebody decide to DOS my 3 IPs that not under floodguard?

Can I simply not use (not setup say in WHM those 3 IPs)?

Or I **must** order more floodguard?

It is very confusely now because SM offers IPs with one step and floodguard with another step.

Can somebody clarify ?

Thank you!..
eddy2099
Well, actually there is no confusion here. The IPs on your plans are what we call useable IPs, those which you can use.

There are 3 other IPs which are used by the Vlan, Gateway and something else which are not useable for you.

If you get say the Floodguard 8 , you are protecting your 5 useable IPs + 3 unuseable IPs.

So basically what you have say for the basic 3 IPs configuration

Floodguard 8 = 5 useable IPs + 3 unuseable IPs (8 IPs)
16 = 13 useable IPs + 3 unuseable IPs (16 IPs)
32 = 29 useable IPs + 3 unuseable IPs (32 IPs)

So if you have 13 useable IPs then the Floodguard 16 IPs would do the trick.

I believe they offer incremental floodguard protection is because that is to ensure that all is protected.

It is like if you have 8 doors in your house and you provide locks for them then you add another 5 more doors without locks. It is not going to mean that the 8 locked doors would protect the 5 unlocked doors.

As far as I understand, the $250 is the fees you pay if you want floodguard installed when you are under a DDoS or DoS attack. It is an escalation charge.

If you do not have floodguard installed and you get flooded, you just pick up the cost of the bandwidth used (including that with is created by the flood and those that is not).

With floodguard, it should mitigate the flooding and redirect it out of your port since it is installed before the router so you will not be charged what is mitigated out.
AlexAT
Thanks, Eddy.
However there are 2 points:

1) AFAIK 8 FloodGuard IP = 8 usable IP.
Where are you take other information from ?

2) About "doors" - when I have 3 IPs not setted up on my server then they won't resolve to my server.
I can be wrong but it seems that.
So and I asked.
Because it seems that you can be DDOS'ed only through setted IPs on your server.

Let I have pool of 32 IPs but use only 2 and have other 30 not setted at all.
And when I put any of those 30 IPs into the browser I get "Page can not be displayed".

So question need to be rephrased - should I protect all allocated IPs or just those that setted on the server?
eddy2099
I came from the old batch of users here and in the days, when they advertised 5 IPs, they did mentioned 2 is useable. It was complicating in the beginning so they revised the way they specify the IPs.

You see the gateway IP address on your Welcome to Servermatrix email. It is an IP near the first useable IP.

If you have not bind the IPs to your machine then you probably do not need it. If you bind them then they are accessible.

Here is one of the earlier posts which I was talking about

http://forums.servermatrix.com/viewtopic.h...ghlight=useable
AlexAT
ok

we are talking here only about **usable** IP.

when I order server with 5 IPs (by default) I get 5 usable IPs.
when I order floodguard for 8 IPs (by default) I get protection for 8 usable IPs.

let I order server with 10 IPs and yes I do not use all of them but SM not allow (or it's not cost effective) to order 6-7-8-9 IPs - just 10.

and let I use only 8.
so I buy floodguard only for 8.

what should I do with others 3 ?
I need protection and I won't be charged for $250 or bandwidth in case of DDOS.
but I do not use them and feel floodfuard for them is unnecessary.

But I want be sure icon_smile.gif
Argyle
If you don't assign the IP you can't be DoSed on it. If you order floodguard for an 8 IP block you can protect 5 IPs.
AlexAT
QUOTE (Argyle)
If you order floodguard for an 8 IP block you can protect 5 IPs.


Where this information taked from?
Argyle
From this post:
http://forums.servermatrix.com/viewtopic.html?t=1558

QUOTE (lcrosby)
The Floodguard system works best when implemented in advance.  When implemented prior to attacks, the sensors "learn" your normal traffic patterns and it helps detect DDOS or Syn Flood traffic.  While we have many tools already in place to mitigate DDOS and Syn Flood on a global network basis, this level of protection assists you if you are the specific target of the attack.  We will be adding a $5 per month option for a single IP (4 IP block...see below).  When we route you a block of 4 IPs, only one is usable...one is assigned to the router, one is for broadcast and the other is your gateway.  Hence 4 IP block = 1 usable IP, 8 IP block = 5 usable IPs, 16 IP block = 13 usable IPs, 32 IP block = 29 usable IPs, etc....  We priced the floodguard to protect all IPs in the range, not just the actual usable IP's.  You will NOT be required to pay $250 if you come under attack, you will only need to pay $250 if you come under attack at a local host level and you wish to implement Floodguard after the fact.  We have priced the product to allow all users to sign up in advance.  Floodguard will be much more effective before the attack because it will have a baseline of your traffic patterns.  After the attack, floodguard must "learn on the fly" so to speak.  It is a very useful tool in mitigating DDOS and Syn Flood attacks and I highly recommend implementing it on all servers.  I hope this helps and let us know if we can further define the offering.
AlexAT
it is old post.

when you order server with 5 IPs you get 5 usable IPs.
when you order additional 8 IPs from orbit you get 8 usable IPs.

that is I just recieved with new server.

seems that not adding IP to the server makes impossible to DDOS server via that IP and makes unnecessary to protect those IPs.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2009 Invision Power Services, Inc.