Table 1. Feature History Table
Feature Name
|
Release Information
|
Description
|
Cisco Secure DDoS Edge Protection
|
Release 7.11.1
|
Introduced in this release on: NCS 5500 fixed port routers; NCS 5700 fixed port routers; NCS 5500 modular routers (NCS 5500
line cards; NCS 5700 line cards [Mode: Compatibility; Native])
We have now moved distributed denial-of-service (DDoS) protection to the network edge, ensuring you can mitigate any DDoS
attacks at the ingress points and minimize the impact of such attacks on your network and applications running on it.
A centralized controller manages DDoS mitigation capabilities using information from a collection of detectors deployed on
the routers. These detectors analyze IPv4 and IPv6 traffic in real-time to identify DDoS attacks. Upon detection, the controller
enforces deny ACLs to block malicious traffic while allowing legitimate traffic.
This local inspection enhances visibility, speeds up response times, and optimizes the network without the need for additional
hardware or attack traffic redirection.
|
The Cisco Secure DDoS Edge Protection software actively halts DDoS attacks at the network entry point, enabling immediate
response to threats. Positioned at the network edge, it identifies and counteracts DDoS threats directly on the router. This
strategy minimizes network and application impact without affecting core bandwidth by avoiding backhaul of malicious traffic.
The DDoS Edge Protection solution helps you detect DDoS attacks and take mitigation actions on the router. To enable detection
services at the core network, you need to configure the following entities:
-
DDoS Edge Protection Controller: This entity manages and monitors the Detector docker application, mitigates attacks, and
oversees a distributed network of edge detectors. It analyzes detection trends across the network, orchestrates cross-network
visibility and mitigation, and provides complete system management for the entire service.
-
DDoS Edge Protection Detector: This entity is a real-time DDoS detection microservice container application that runs as a
docker-application on a router with the DDoS controller. The DDOS controller can run on a cloud, server, or customer premises
and is connected to this application.
The DDoS Edge Protection supports DDoS detection of both IPv4 and IPv6 traffic. You can choose the interface on which the
traffic should be monitored. When the protection software solution is implemented, it filters the IPv4/IPv6 traffic flow and
detects DDoS attacks.
Once a DDoS attack is detected, the DDoS Edge Protection Controller initiates a mitigation action, specifying the necessary
steps to counteract the attack. This includes enabling traffic classification (TC) as part of the mitigation measures, implementation
of rate limiting and so on.
Supported Routers
Cisco Secure DDoS Edge Protection is supported on the following hardware:
-
NCS-55A1-48Q6H
-
NCS-55A1-48Q6H-SE
-
NCS-55A1-48Q-DTC
-
NCS-57D2-18DD-S
-
NCS-57C3-MOD-S
-
NCS-57C3-MOD-SE-S
-
NCS-55A1-36H-SE-S
-
NCS-55A1-36H-DTC
-
NCS-55A1-36H-GLE
-
NCS-55A1-36H-S
-
NCS-55A2-MOD-SE-S
-
NCS-55A2-MOD-HD-S
-
NCS-55A2-MOD-SYS
-
NCS-55A2-MOD-HX-S
-
NCS-55A2-MOD-SE-H-S
-
NCS-55A1-24H
-
NCS-57B1-6D24H-S
-
NCS-57B1-5D24H-SE
-
NCS-5501
-
NCS-5501-SE
-
NCS-55A1-24Q6H-S
-
NCS-55A1-24Q-DTCR
-
NCS-55A1-24Q-RPHY
-
NCS-55A1-24Q6H-SS
-
NCS-57C1-48Q6D-S
-
NCS-5502-SE
-
NCS-5502-U100
Benefits of Cisco Secure DDoS Edge Protection
-
Stops DDoS attacks at the network ingress
-
Requires no additional hardware or facilities such as power, rack space, and cooling
-
Requires no changes to the architecture
-
Avoids the need to overprovision network facilities such as links and routers to account for attack traffic
-
Prevents backhauling of malicious traffic
-
Minimizes network outages and optimizes the end-user experience, and
-
Meets low-latency application requirements.