DDoS Protectionঅপারেটর রানবুক

Mitigation, BGP ও Recovery

Verified response connector configure, critical address protect, সীমিত mitigation approve এবং recovery verify করুন।

সহায়তা নিন
এই পৃষ্ঠায়

Response connector ছাড়াই detection কাজ করে। Organisation-এর authorised network design, approval policy, independent verification method এবং tested rollback owner থাকলেই mitigation configure করুন।

RTBH announced target-এর সব traffic discard করে, blocklist over-match করতে পারে এবং scrubbing-এর জন্য compatible routing-সহ contracted provider দরকার। Accepted API request mitigation কার্যকর হওয়ার প্রমাণ নয়।

Approval mode বেছে নিন

Mode আচরণ
Manual queue Authorised responder প্রতিটি action স্পষ্টভাবে queue করেন।
Single approval Proposal একজন authorised responder-এর অপেক্ষা করে।
Dual control দুইজন আলাদা authorised responder approve করেন।
Verified automatic Eligible critical detection verified connector queue করতে পারে; scope, exclusion, entitlement ও permission safeguard তবু প্রযোজ্য।

Connector configure ও verify করুন

Response & BGP খুলুন। Supported design-এর মধ্যে RouterOS RTBH, RouterOS local exact-host blackhole, contracted scrubbing provider, blocklist, external BGP neighbour এবং webhook আছে। External route, session, endpoint বা device state verify না হওয়া পর্যন্ত নতুন connector Pending থাকে।

ISPbills RouterOS peer configure করুন

  1. Connected RouterOS 7 device select করে Configure ISPbills BGP peer বেছে নিন।
  2. Router record, management endpoint, local/remote ASN, BGP endpoint ও multihop design review করুন।
  3. Cloud security group, host firewall ও NAT দিয়ে real peer endpoint-এর TCP/179 allow করুন।
  4. RouterOS ও ISPbills speaker দুটোই Established দেখানো পর্যন্ত অপেক্ষা করুন।
  5. প্রথম response-এর আগে active announcement count শূন্য নিশ্চিত করুন।

One-click setup dedicated router instance, inbound exact-host blackhole policy, outbound deny policy এবং eBGP multihop session তৈরি করে। Setup incident target announce করে না। Approved incident শুধু detected IPv4 /32 blackhole community 65535:666 দিয়ে announce করতে পারে; wider prefix reject হয় এবং expiry-তে route withdraw হয়।

Critical address protect করুন

Peering, point-to-point, authoritative DNS, management, monitoring, collector, BGP এবং essential address Mitigation allowlist-এ যোগ করুন। Detection চলতে পারে, কিন্তু excluded address-এর manual ও automatic action reject হয়।

Automatic safety perimeter tenant router, OLT, switch ও radio management address, gateway, connector endpoint এবং suspended-user pool-ও পরীক্ষা করে। Proposal, approval, sensor claim ও final execution-এ এটি আবার evaluate হয়।

সবচেয়ে সীমিত response propose করুন

  1. Exact target protected scope-এর ভেতরে আছে নিশ্চিত করুন।
  2. Connector Ready এবং actual external state verify করুন।
  3. সবচেয়ে narrow supported target ও shortest practical duration নিন।
  4. Expected customer impact ও rollback method লিখুন।
  5. Configured approval workflow দিয়ে request submit করুন।
  6. Incident timeline-এ claim, execution, expiry, cancellation বা failure দেখুন।

Verify ও recover করুন

  1. ISPbills-এর বাইরে route, provider, blocklist বা device state নিশ্চিত করুন।
  2. BPS, PPS, FPS, packet loss, latency ও affected service পরীক্ষা করুন।
  3. Traffic অন্য target বা address family-তে সরে যাচ্ছে কিনা দেখুন।
  4. যে connector change apply করেছে সেটি দিয়েই withdraw/rollback করুন।
  5. Route/rule চলে গেছে এবং service stable তা নিশ্চিত করুন।
  6. Incident Resolved করে evidence ও runbook improvement লিখে রাখুন।

Response troubleshooting

  • Pending connector: actual endpoint, peer, route বা device state verify করুন।
  • BGP established নয়: endpoint reachability, TCP/179, ASN, multihop, NAT, firewall ও দুই peer state পরীক্ষা করুন।
  • Proposal rejected: protected scope, exclusion, entitlement, permission, readiness ও lifecycle দেখুন।
  • উন্নতি নেই: execution independently confirm, target/vector আবার দেখুন এবং scope অন্ধভাবে না বাড়িয়ে upstream/scrubber-এ escalate করুন।
  • Withdrawal অসম্পূর্ণ: connector rollback path ব্যবহার করে active route/rule inspect করুন।

Event চলাকালে printable DDoS Protection → Runbook এবং attack investigation guide একসঙ্গে ব্যবহার করুন।

আরও সাহায্য দরকার?সম্পর্কিত নির্দেশিকা দেখুন অথবা আমাদের সহায়তা দলের সাথে যোগাযোগ করুন।