Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> Putting an IP address filter on that endpoint is usually enough to stop that.

Why is there even direct external IP connectivity to the realserver, sidestepping the loadbalancer?



Not all load balancers function at the same OSI layer. If you are using an IP based load balancer with transparent NAT, you don't really have a choice. Requests will be balanced across systems to that health check, but it's still a DOS if it's intensive enough to serve and someone hammers it hard enough.


Lots of times companies will have a 3rd party firm do their availability monitoring for them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: