josh wrote:We did have a spike in usage earlier today caused by at least two user accounts with scripted address creation going on -- hard to say whether this is a DOS, or just a user trying to pull a fast one on somebody else (registering a bunch of times, or whatever). Those were cut off.
Most interesting that it leads to packet loss on last hop. It would mean that bandwidth was saturated. Usually I'm used to situations where server power runs out before network is being severly flooded. Especially with services which include database / active page creation and so.
Other than that, it's been a busy day, but I haven't been seeing the issues you're talking about -- what part of the world are you in?
Finland
But as I mentioned, because all problems existed only with last hop, it's (almost) meaningless where the tracert or ping originated from. There might be some very moronic routing problem which could affect, but it's not too common.
It's good to keep in mind that the weakest link with SG is bandwidth. It means that DDoSin should be relatively easy. What kind of BW you got? 100 megabits, gigabit? Or something much less than that?