Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


FoD is currently provided as a production service in the GÉANT core network using FoD software based on flowspy v1.18.

FoD v1.5 is in pilot phase. It adds support for explicit port ranges in rule specifications  allowing more convenient mitigation with less rules, provides a multi-tenant REST-API allowing for automated user mitigation instead of manual one with WebUI,  and provides rule mitigation statistics for user feedback.

FoD v1.6 is in design/development phase. It will provide automated rule proposals created out of DDoS events and information, in case of GÉANT particularly out of NSHaRP (Network Security Handling and Response Process) DDoS events.

FoD v1.8 upgrades the underlying software framework the platform is build upon to the most recent version. It also added IPv6 support for injecting routes into the GÉANT core network, fixed bugs and added a few enhancement to the user interface.

Users


FoD users are connected NRENs or recursively connected institutions with their own AS; especially the NoC admins of these organizations

...

All operations, business development and stakeholders contacts 


 
Service ManagerDeputy Service ManagerL1 supportL2 supportL3 support
Evangelos Spatharas

 support@oc.geant.net

 security@geant.org

fod@lists.geant.org


...

In GÉANT, FoD, currently running v1.18, for GÉANT core network, is operated by GÉANT NOC. FoD users are all NREN NOCs as well as any recursively connected institutions having their own AS. Any potential user can subscribe to FoD service and afterwards use the service, that can be accessed it via the web portal address. Authentication of users is based on eduGAIN.

...

FoD support eduGAIN logins for its users, based on apache edugain support.

FoD (along with apache with edugain support, a mysql database and a supporting software beanstalk)  is run on a single VM with possibility to connect a particular core router  via NETCONF for pushing its BGP FlowSpec rules.
In addition to that the v1.5 8 being currently in pilot support creation of creation of rule drop statistics for user feedback by using SNMP to all core routers.

...