Wanguard 6.2 User Guide
Appendix 3 – BGP Black Hole Guideline for Wanguard Sensor
Appendix 3 – BGP Black Hole Guideline for Wanguard Sensor
Understanding
of RTBH using Wanguard
To simplify, we will start from the following scenario: an attack is detected by
Wanguard Sensor (hereby
referred simply as
Sensor
) that decides to react by using the BGP black hole approach rather than diverting traffic for
scrubbing by Wanguard Filter.
In RTBH setup,
Sensor
would play the role of
Trigger
.
After an attack is detected,
Sensor
signals the
IBR
(Internet Border Router) via BGP that all traffic destined to
IPv4-Victim
has to be dropped. In more details:
Sensor
advertises via BGP an
IPv4-Victim
/32 prefix with a specific community to be identified as a Black
Hole announcement
The IBR receives the announcement and it inserts the route in its routing table as
IPv4-Victim
/32 with
next-hop Null0.
Furthermore, the
IBR
advertises this route to its upstream providers (
ISP
s) changing at the same time
the community used for internal purposes, to a community which is relevant to the correspondent ISP.
For a better understanding you may refer to the diagram below:
- 109 -
Summary of Contents for wanguard 6.2
Page 1: ......