BGP FlowSpec on NCS5500: A few tests on scale, rate and memory usage
We published a couple of videos on BGP FS earlier this year but never finalized the effort with a proper xrdocs.io blog post.
After a couple of months, I gathered questions from customers and used this opportunity to finally publish on the NCS5500 implementation of BGP Flowspec.
You'll find in this article:
- the specifics of the NCS5500 implementation (hardware profile, interface support, recirculation, ...)
- a review of the resources used to store the rules and the stats
- an "analysis" of the memory space consumed by common rules used in DDoS mitigation and more particularly the rules auto-generated by the Netscout/Arbor SP for amplification attacks
- the speed to program entries in external TCAM
- the behavior when the supported scale is exceeded
https://xrdocs.io/ncs5500/tutorials/bgp-flowspec-on-ncs5500/
Business Developer | Program Leader | Service Owner | Leader | Network and Systems Architect | Dad | Technologist | Transformer | Connector | Mentor | Business Development | Digital Transformer | Learning all the time
5 年In Nicholas we trust. Thanks Sir!