DDoS Protectionঅপারেটর রানবুক

Telemetry ও Protected Scope Configure করুন

অনুমোদিত network ঘোষণা, RouterOS বা external flow telemetry connect, source health verify এবং monitoring activate করুন।

সহায়তা নিন
এই পৃষ্ঠায়

নির্ভরযোগ্য DDoS detection-এর শুরু সঠিক network profile, অনুমোদিত protected prefix এবং স্বাধীনভাবে observed flow record দিয়ে। DDoS Protection → SetupTelemetry-তে ধাপগুলো সম্পন্ন করুন।

Network profile সম্পন্ন করুন

Organisation name, monitored capacity, baseline learning window এবং NOC notification email দিন। BGP response বা routing-context analysis পরিকল্পনা থাকলে local ASN যোগ করুন। Attack প্রথম দেখা গেলে in-product owner alert তৈরি হয় এবং NOC address-এ summary queue হয়।

Protected scope ঘোষণা করুন

শুধু organisation-এর মালিকানাধীন বা monitor করার অনুমতি থাকা public/private IPv4 বা IPv6 space যোগ করুন। CIDR অথবা একটি host দিন; single host IPv4 /32 বা IPv6 /128 হিসেবে save হয়।

  • Subscriber ও service address space
  • Infrastructure ও management range
  • Point-to-point, transit ও peering segment
  • Monitor করা দরকার এমন private service network

Protected scope কোথায় detection এবং approved exact-host response অনুমোদিত তা নির্ধারণ করে। Address যোগ করলে তা announce, block বা scrub হয় না; protected scope mitigation allowlist-ও নয়।

Telemetry source যোগ করুন

Telemetry খুলে প্রযোজ্য type, name, site, exporter address ও listen port দিন। Supported source:

  • sFlow
  • NetFlow v5 ও NetFlow v9
  • IPFIX
  • Managed sensor-এ observed SPAN বা mirrored traffic
  • AWS VPC Flow Logs
  • Google Cloud VPC Flow Logs

Connected RouterOS device configure করুন

  1. Telemetry থেকে Configure Traffic Flow in one step বেছে নিন।
  2. Connected router এবং NetFlow v5/v9 বা IPFIX select করুন।
  3. Read-only managed collector address, reserved port এবং ছয় অক্ষরের service ID review করুন।
  4. Saved RouterOS API connection দিয়ে configuration apply করুন।
  5. Source healthy ধরার আগে ISPbills-এর real flow record decode হওয়া পর্যন্ত অপেক্ষা করুন।

RouterOS API 8728 ও API-SSL 8729 supported। Managed collector প্রতিটি exporter-এর template ও baseline state আলাদা রাখে।

Self-managed sensor connect করুন

sFlow, SPAN ও cloud-log source-এর জন্য authenticated sensor contract-এ observation normalise করা deployed sensor বা adapter দরকার। Tenant-operated collector-এর প্রয়োজন হলেই optional sensor token reveal/rotate করুন, সরাসরি secret manager-এ copy করুন এবং মনে রাখুন rotation আগের token সঙ্গে সঙ্গে invalid করে।

Source health সঠিকভাবে পড়ুন

State অর্থ ও করণীয়
Pending Definition save হয়েছে, decoded record verify হয়নি। Exporter setting, credential, address, port, NAT ও firewall path পরীক্ষা করুন।
Healthy Decoded record current। Exporter, latest flow rate এবং verification time intended source-এর সঙ্গে মিলিয়ে নিন।
Stale Record আসা বন্ধ। Exporter, sensor process, template, clock এবং reachability পরীক্ষা করুন।
Degraded profile Reliable current source নেই। Detection বা empty attack queue-এর ওপর নির্ভর করার আগে telemetry restore করুন।

Successful RouterOS API call বা শুধু UDP packet আসা healthy telemetry নয়। ISPbills decoded flow record বা সফল adapter report-এর অপেক্ষা করে।

Monitoring activate করুন

Protected scope, telemetry ও required detection policy প্রস্তুত হলে setup checklist review করে Activate monitoring select করুন। Activation baseline learning ও policy evaluation শুরু করে; response connector চালায় না। Learning window-এ detection absolute threshold-এর ওপর বেশি নির্ভর করতে পারে।

Telemetry checklist

  • Displayed exporter ও site intended device-এর সঙ্গে মেলে।
  • Last verified record time recent এবং এগোচ্ছে।
  • BPS, PPS ও FPS interface counter-এর তুলনায় plausible।
  • দুই address family protected হলে IPv4 ও IPv6 source আছে।
  • Collector credential ও sensor token ticket/chat-এর বাইরে সংরক্ষিত।

পরবর্তী ধাপ: detection policy ও analytics configure করুন

আরও সাহায্য দরকার?সম্পর্কিত নির্দেশিকা দেখুন অথবা আমাদের সহায়তা দলের সাথে যোগাযোগ করুন।