Protection Against UDP Flooding
UDP flooding is a type of DDoS attack that is intended to slow down a system. In this attack, the receiver needs to process every UDP packet and send an ICMP Error message if no service is running on the destination port specified in the UDP header. If the source IP address in the UDP attack packet is spoofed, the ICMP error message is sent to the spoofed IP address. To mitigate UDP flooding, you can globally configure UDP packet rate limiting. There are two types of packets:
- Packets coming in on a data port (Data packets) - Any UDP packet received by ICX devices on any data port can be rate-limited. The rate limit value can be configured globally.
- Packets coming to the CPU (Control packets) - Unicast and multicast UDP packets sent to the CPU by Forwarding Database (FDB) or Route Entry lookup can be subject to rate limiting. The rate limit can be configured for a range of UDP destination ports or for all ports and for a customized packet burst threshold. When the threshold is exceeded, all UDP packet traffic on the configured ports is limited to 125 packets per second.
To mitigate UDP flooding:
1. Define the ports for which DDoS protection should be enabled.
2. Configure a rate limit for UDP unicast and multicast packets destined to CPU.
There is no support to proactively drop all the UDP packets that are sent to the CPU.