I think those ddos attacks where using port 80 outbound. It'll piss off 99.9999999999999999999999999999999999999999999% of your customers, but that doesn't matter.
said by reub2000:I think those ddos attacks where using port 80 outbound. It'll piss off 99.9999999999999999999999999999999999999999999% of your customers, but that doesn't matter.
In resonse to these DDOS attacks, ISPs put pressure on router vendors so that Cisco and others produced advanced filtering features such as NBAR. When these attacks were prevalent, I was able to put filters that blocked web requests for *default.ida*, and other very specific requests. Not many people noticed these filters.