nanog mailing list archives

Re: RTBH Support Across the Industry


From: David Bass via NANOG <nanog () lists nanog org>
Date: Mon, 27 Jul 2026 16:14:05 -0500

RTBH is absolutely used to thwart DDOS attacks right now in production at
some extremely large, and constantly attacked organizations that I’ve
personally seen.

As far as use by attackers…possibly used as well, but haven’t witnessed
this one.

David

On Mon, Jul 27, 2026 at 2:50 AM Saku Ytti via NANOG <nanog () lists nanog org>
wrote:

Is there consensus that RTBH is desirable?

Isn't RTBH just aiding the attacker and extending the duration of
outage outside the duration of attack? With RTBH implemented, how do
we know when the issue subsides? Do we periodically remove RTBH to
check?

I think downgrading traffic to scavenger class via a BGP community is
superior to RTBH, you are transporting as much as you can, but
yielding to best effort. This gives you observability, you know when
the issue subsides, as you're still getting the packets, so you can
automatically remove the downgrade, the moment the attack subsides.
On your end you can push this market traffic to monitor box, scrubber
box, through ACL, null0 or whatever is locally prudent right now.


On Mon, 27 Jul 2026 at 10:41, James Bensley via NANOG
<nanog () lists nanog org> wrote:

Dear Community,

RTBH is not as effective as it could be, for various reason, just a few
include:

* Not all networks support RTBH.
* Networks that do support RTBH implement it differently to each other.
* There is no one place where one can easily find the info for how to
use RTBH with a given network.
* Operators have different ideas about how / when / where / why someone
should / shouldn't use RTBH.

To this end, below is the first of two surveys. This first one is
quantitative and captures how networks have implemented RTBH and provides
(1) a public repository which anyone can use to look-up the RTBH details
for their peers/upstreams, and (2) an insight into the (mis-)alignment of
RTBH implementations across the industry.

Please take the time to fill out the short survey for your own network
(even if you don't support RTBH!), and if you can, please fill it out for
other networks where you know how they have implemented RTBH (e.g., peers
you use RTBH with):
https://docs.google.com/forms/d/e/1FAIpQLScg2Bvr_14onOtZRdoK2SNd0kCHFtqsdw-elsO5miUAO-3zzg/viewform

(^ No login required)

The data ends up in this public repository (you can of course make a
pull request directly if you want):
https://remotely-triggered-black-hole.github.io/rtbh/

The second survey will be qualitative, to gather information from the
industry community on why you do / don't support RTBH, when do you use it,
how do you think the routing should be secured, etc.

The long term goal is to use the data from both surveys as input in to a
community effort to improve RTBH alignment across the industry and improve
it's effectiveness for all (e.g. maybe produce a new BCOP for implementing
RTBH, or usage guidelines for blackholing, or maybe a new RFC is required
to secure the filtering; regardless, the first step is to gather data about
the status quo and review that data to get a baseline of where we are at
today).

Any questions, please let me know, and thank you for your time and help,
it is appreciated.

With kind regards,
James_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/LOWUU7RHOKTYKVGWRHNXQJ3GSJYN3HLE/



--
  ++ytti
_______________________________________________
NANOG mailing list

https://lists.nanog.org/archives/list/nanog () lists nanog org/message/ITDOCC6N5VELZ56F6ILVZODZSUWH3TNE/

_______________________________________________
NANOG mailing list 
https://lists.nanog.org/archives/list/nanog () lists nanog org/message/KH6VPK6DSMZ3R4PCZXTSVVKXHXD7COCE/

Current thread: