Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Asymmetric POSTer
Aug 17, 2005

Sniep posted:

a problem more cheaply solved for with a varnish or nginx proxy in front of the sa origins with separate addressing vs paying cloudflare rates but *shrugs*

:effort:

Adbot
ADBOT LOVES YOU

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

akadajet posted:

ya. i'd never know cloudflare existed if they didn't keep showing their poo poo to me when stuff breaks

lowtax can turn that off by enabling origin error pages btw, it's optional to use cloudfront's middleman errors and they don't intend to inject them as a branding effort its more diagnostic help



💸

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano

Sniep posted:

a problem more cheaply solved for with a varnish or nginx proxy in front of the sa origins with separate addressing vs paying cloudflare rates but *shrugs*

hows this gonna stand up against some kid with a tens of gbps's booter

you need to hide your origin ips cos as soon as they get hit directly your upstream provider is gonna nullroute them, you cant jump behind cloudflare at that point cos its too late

SmokaDustbowl
Feb 12, 2001

by vyelkin
Fun Shoe

Rufus Ping posted:

you need to hide your origin ips cos as soon as they get hit directly your upstream provider is gonna nullroute them, you cant jump behind cloudflare at that point cos its too late

lol

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
there's like 835915 better answers than just paying cloudflare to do it

if you dont wanna have your own frontend to protect your origins fine, get a shittier cheap CDN to do it, still end of the day a DNS flip to put cloudflare in front and only pay for it when you need it

i've done this multiple times, it's not hard, but hey feel free to pay cloudflare all of the money you want to

qhat
Jul 6, 2015


gently caress cloudflare!!!

akadajet
Sep 14, 2003

qhat posted:

gently caress cloudflare!!!

:yeah:

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast
lol blaming cloudflare for SA's origin going down because richard doesn't disable the diagnostic page on cloudflare is lol

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
what am i missing? ime the immediate reaction of most hosts is to promptly poo poo themselves and blackhole your ips upstream of their routers. they'd probably be pretty reluctant to give you new ips if the ddos is ongoing

Sniep posted:

there's like 835915 better answers than just paying cloudflare to do it
you dont have to pay them at this point, you can just have a free account then swap to paid if you need to. but i'm interested what the alternatives are. i'm aware of the post-hoc ddos mitigation services that announce your routes via bgp and scrub the traffic but this isn't much use if you don't have your own AS

Sniep posted:

i've done this multiple times, it's not hard, but hey feel free to pay cloudflare all of the money you want to
ive got a free business-tier plan fwiw so this is all academic

post hole digger
Mar 21, 2011

cloud flare is fine.

SmokaDustbowl
Feb 12, 2001

by vyelkin
Fun Shoe

Rufus Ping posted:

what am i missing? ime the immediate reaction of most hosts is to promptly poo poo themselves and blackhole your ips upstream of their routers. they'd probably be pretty reluctant to give you new ips if the ddos is ongoing

isp doesn't care as you pay your bill

Asymmetric POSTer
Aug 17, 2005

SmokaDustbowl posted:

isp doesn't care as you pay your bill

lol

Asymmetric POSTer
Aug 17, 2005

Rufus Ping posted:

but i'm interested what the alternatives are. i'm aware of the post-hoc ddos mitigation services that announce your routes via bgp and scrub the traffic but this isn't much use if you don't have your own AS

+1

i don't get how dns fuckery alone will fix a direct attack on the actual servers

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

mishaq posted:

+1

i don't get how dns fuckery alone will fix a direct attack on the actual servers

it wont - you flip from your own frontends or other cheaper cdn over to cloudflare via DNS as in this circumstance it's implied you've protected the IP addressing/hardware all along from attack you're just shifting to a bigger shield.

the neustar / bgp angle is, as mentioned above, not applicable to many/most people's setups

all im saying is there are other options vs. paying cloudflare to proxy a high hit site like this 24/7/365

Asymmetric POSTer
Aug 17, 2005

Sniep posted:

it wont - you flip from your own frontends or other cheaper cdn over to cloudflare via DNS as in this circumstance it's implied you've protected the IP addressing/hardware all along from attack you're just shifting to a bigger shield.

the neustar / bgp angle is, as mentioned above, not applicable to many/most people's setups

all im saying is there are other options vs. paying cloudflare to proxy a high hit site like this 24/7/365

i gotcha

akadajet
Sep 14, 2003

Sniep posted:

lol blaming cloudflare for SA's origin going down because richard doesn't disable the diagnostic page on cloudflare is lol

i'm just a clueless end user

Sniep
Mar 28, 2004

All I needed was that fatty blunt...



King of Breakfast

akadajet posted:

i'm just a clueless end user

me too now and it owns

akadajet
Sep 14, 2003

Sniep posted:

me too now and it owns

https://www.youtube.com/watch?v=OLv6ycYcpGI&hd=1&t=21s

FamDav
Mar 29, 2008

Sniep posted:

it wont - you flip from your own frontends or other cheaper cdn over to cloudflare via DNS as in this circumstance it's implied you've protected the IP addressing/hardware all along from attack you're just shifting to a bigger shield.

the neustar / bgp angle is, as mentioned above, not applicable to many/most people's setups

all im saying is there are other options vs. paying cloudflare to proxy a high hit site like this 24/7/365

biggest concern here is knowing you can do this switchover effectively and w/o any unintended behavioral changes. though if this is really a lifesaver type of situation then why the heck not

pram
Jun 10, 2001
if they have your origin ip it doesnt matter

Asymmetric POSTer
Aug 17, 2005

the point is the only "origin" ips that should be exposed are your front end which you switch over in the event of an attack

they can keep attacking the old front end as long as they want

pram
Jun 10, 2001
thats not how it works you loving morons. cloudflare is literally your domain ns. your A record to your 'front end' would have to be in cloudflare, served through their servers. you can't 'switch over' without waiting for the propagation and everyones dns cache to expire which makes what youre all describing utterly pointless

pram
Jun 10, 2001
are you maintaining a secret 'front end' which is a different ip and completely unused ??

Asymmetric POSTer
Aug 17, 2005

pram posted:

are you maintaining a secret 'front end' which is a different ip and completely unused ??

that's the only way it could work, yeah

have the second front end in aws or whatever and only break glass in emergency

pram
Jun 10, 2001
of course it makes sense to have a second unused load balancer instead of using a free cloudflare account. you are all unironically great consultants lol

Rufus Ping
Dec 27, 2006





I'm a Friend of Rodney Nano
i dont know why youd bother with all that convoluted poo poo when you can just use free cloudflare (with all the caching features disabled if you want) and then turn "im being attacked" mode on should you need it

Asymmetric POSTer
Aug 17, 2005

:grin:

FamDav
Mar 29, 2008
i just go with whatever weird premise people are working off of

pram
Jun 10, 2001

Rufus Ping posted:

i dont know why youd bother with all that convoluted poo poo when you can just use free cloudflare (with all the caching features disabled if you want) and then turn "im being attacked" mode on should you need it

because theyre idiots

Asymmetric POSTer
Aug 17, 2005

im just trying to decipher how what sniep is talking about would work :shrug:

pram
Jun 10, 2001
its fundamentally dumb. you switch over your NS records, guess what:

1) your main frontend is still getting hammered, and your backend systems are obviously STILL affected
2) your backup frontend is still proxying to the hammered systems
3) your DNS is now in limbo, who knows when your customers caches expire
4) you can shut your old frontend off but your site is now literally dead for everyone resolving to the old NS
5) the attackers still know your old frontend IP so lol

Asymmetric POSTer
Aug 17, 2005

go ipv6 only and constantly rotate through a billion different ips, like when they alternate shield frequencies in star trek :c00l:

akadajet
Sep 14, 2003

mishaq posted:

go ipv6 only and constantly rotate through a billion different ips, like when they alternate shield frequencies in star trek :c00l:

my isp gives me a new ip6 ip like every day. makes vandalizing wikipedia a piece of cake

Adbot
ADBOT LOVES YOU

echinopsis
Apr 13, 2004

by Fluffdaddy
wow you guys weren't kidding you really are
a bunch of nerds

  • Locked thread