I'll be happy to answer any questions you have regarding our service either here or through our support channels.
I'll be happy to answer any questions you have regarding our service either here or through our support channels.
I feel for the operational folks at Zerigo - dealing with this type of outage is hard. The best thing they can do at this point is get back on Twitter and talk to their customers - the last post was 4 hours ago - that's a lifetime when your system is critical.
How much computing power and attack traffic can those really handle?
If you are going to offer a solution to a massive DDoS I would think that you would be careful on when to propose your solution.
Instead of adding another unicast network to the mix, why wouldn't you start using an IP anycast network?
Please explain how much capacity you have.
Great product, great support, great team, great price.
Recommended.
* How much DNS traffic can it handle for one customer? Usually DNS-services that charge much more than DNSimple have this capped.
* 99% availability (3.65d/y) sounds a bit too much for a production server DNS SLA, maybe after introducing a secondary DNS a much higher availability could be offered. Any timeline for adding a secondary DNS?
* We don't have a timeline, but we have been working on it. We'd like to roll out support for secondary NOTIFY and AXFR, but perhaps we can find a short term solution without that.
However, what I would like to know is - have you guys implemented any procedures to mitigate any negative effects a DDoS may have on your services? (Assuming your service gets DDoS'd like Zerigo) The last thing I want is more down time and to switch to another provider once again.
Even more impressive is we have directed a couple very non-technical customers to them and they all have been able to get up and running in no time.
That said, I don't know anything about Zerigo and I have no opinion about them.
We'll post a more extensive post-mortem once we have a better understanding of what happened, but our main goal at the moment has been to ensure systems remain stable and responsive.
- The downtime was 40 minutes (according to Pingdom), that isn't short for something as critical as DNS.
- It seems off to pimp yourself on a thread about a competitors downtime, especially when you had a significant one at pretty much the same time.
Can any unicast provider even really get close to fighting an attack like this?
Let's be serious at some point.... 6 servers... the MOST you can push is 6 Gbps. And most likely they are bound to about 400 Mbps of DNS traffic (based on CPU load). Unless you have hundreds of name servers and multiple locations... are you even really competing in uptime anymore?