1"use strict";(self.webpackChunktigera_docs=self.webpackChunktigera_docs||[]).push([["2869"],{37812(e,t,n){n.r(t),n.d(t,{metadata:()=>i,default:()=>h,frontMatter:()=>s,contentTitle:()=>a,toc:()=>c,assets:()=>l});var i=JSON.parse('{"id":"network-policy/extreme-traffic/defend-dos-attack","title":"Defend against DoS attacks","description":"Define DoS mitigation rules in Calico policy to quickly drop connections when under attack. Learn how rules use eBPF and XDP, including hardware offload when available.","source":"@site/calico_versioned_docs/version-3.29/network-policy/extreme-traffic/defend-dos-attack.mdx","sourceDirName":"network-policy/extreme-traffic","slug":"/network-policy/extreme-traffic/defend-dos-attack","permalink":"/calico/3.29/network-policy/extreme-traffic/defend-dos-attack","draft":false,"unlisted":false,"editUrl":"https://github.com/tigera/docs/edit/main/calico_versioned_docs/version-3.29/network-policy/extreme-traffic/defend-dos-attack.mdx","tags":[],"version":"3.29","frontMatter":{"description":"Define DoS mitigation rules in Calico policy to quickly drop connections when under attack. Learn how rules use eBPF and XDP, including hardware offload when available."},"sidebar":"calicoSidebar","previous":{"title":"Enable extreme high-connection workloads","permalink":"/calico/3.29/network-policy/extreme-traffic/high-connection-workloads"},"next":{"title":"Encrypt in-cluster pod traffic","permalink":"/calico/3.29/network-policy/encrypt-cluster-pod-traffic"}}'),o=n(70689),r=n(3413);let s={description:"Define DoS mitigation rules in Calico policy to quickly drop connections when under attack. Learn how rules use eBPF and XDP, including hardware offload when available."},a="Defend against DoS attacks",l={},c=[{value:"Big picture",id:"big-picture",level:2},{value:"Value",id:"value",level:2},{value:"Concepts",id:"concepts",level:2},{value:"Earliest packet processing",id:"earliest-packet-processing",level:3},{value:"How to",id:"how-to",level:2},{value:"Best practice",id:"best-practice",level:3},{value:"Step 1: Create host endpoints",id:"step-1-create-host-endpoints",level:3},{value:"Step 2: Add CIDRs to deny-list in a global network set",id:"step-2-add-cidrs-to-deny-list-in-a-global-network-set",level:3},{value:"Step 3: Create deny incoming traffic global network policy",id:"step-3-create-deny-incoming-traffic-global-network-policy",level:3},{value:"Additional resources",id:"additional-resources",level:2}];function d(e){let t={a:"a",admonition:"admonition",code:"code",h1:"h1",h2:"h2",h3:"h3",header:"header",li:"li",p:"p",pre:"pre",strong:"strong",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",ul:"ul",...(0,r.R)(),...e.components};return(0,o.jsxs)(o.Fragment,{children:[(0,o.jsx)(t.header,{children:(0,o.jsx)(t.h1,{id:"defend-against-dos-attacks",children:"Defend against DoS attacks"})}),"\n",(0,o.jsx)(t.h2,{id:"big-picture",children:"Big picture"}),"\n",(0,o.jsx)(t.p,{children:"Calico automatically enforces specific types of deny-list policies at the earliest possible point in the packet processing pipeline, including offloading to NIC hardware whenever possible."}),"\n",(0,o.jsx)(t.h2,{id:"value",children:"Value"}),"\n",(0,o.jsx)(t.p,{children:"During a DoS attack, a cluster can receive massive numbers of connection requests from attackers. The faster these connection requests are dropped, the less flooding and overloading to your hosts. When you define DoS mitigation rules in Calico network policy, Calico enforces the rules as efficiently as possible to minimize the impact."}),"\n",(0,o.jsx)(t.h2,{id:"concepts",children:"Concepts"}),"\n",(0,o.jsx)(t.h3,{id:"earliest-packet-processing",children:"Earliest packet processing"}),"\n",(0,o.jsx)(t.p,{children:"The earliest point in the packet processing pipeline that packets can be dropped, depends on the Linux kernel version and the capabilities of the NIC driver and NIC hardware. Calico automatically uses the fastest available option."}),"\n",(0,o.jsxs)(t.table,{children:[(0,o.jsx)(t.thead,{children:(0,o.jsxs)(t.tr,{children:[(0,o.jsx)(t.th,{children:"Processed by..."}),(0,o.jsx)(t.th,{children:"Used by Calico if..."}),(0,o.jsx)(t.th,{children:"Performance"})]})}),(0,o.jsxs)(t.tbody,{children:[(0,o.jsxs)(t.tr,{children:[(0,o.jsx)(t.td,{children:"NIC hardware"}
1),(0,o.jsxs)(t.td,{children:["The NIC supports ",(0,o.jsx)(t.strong,{children:"XDP offload"})," mode."]}),(0,o.jsx)(t.td,{children:"Fastest"})]}),(0,o.jsxs)(t.tr,{children:[(0,o.jsx)(t.td,{children:"NIC driver"}),(0,o.jsxs)(t.td,{children:["The NIC driver supports ",(0,o.jsx)(t.strong,{children:"XDP native"})," mode."]}),(0,o.jsx)(t.td,{children:"Faster"})]}),(0,o.jsxs)(t.tr,{children:[(0,o.jsx)(t.td,{children:"Kernel"}),(0,o.jsxs)(t.td,{children:["The kernel supports ",(0,o.jsx)(t.strong,{children:"XDP generic mode"})," and Calico is configured to explicitly use it. This mode is rarely used and has no performance benefits over iptables raw mode below. To enable, see ",(0,o.jsx)(t.a,{href:"/calico/3.29/reference/resources/felixconfig",children:"Felix Configuration"}),"."]}),(0,o.jsx)(t.td,{children:"Fast"})]}),(0,o.jsxs)(t.tr,{children:[(0,o.jsx)(t.td,{children:"Kernel"}),(0,o.jsxs)(t.td,{children:["If none of the modes above are available, ",(0,o.jsx)(t.strong,{children:"iptables raw"})," mode is used."]}),(0,o.jsx)(t.td,{children:"Fast"})]})]})]}),"\n",(0,o.jsx)(t.admonition,{type:"note",children:(0,o.jsx)(t.p,{children:"XDP modes require Linux kernel v4.16 or later."})}),"\n",(0,o.jsx)(t.h2,{id:"how-to",children:"How to"}),"\n",(0,o.jsx)(t.p,{children:"The high-level steps to defend against a DoS attack are:"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"#step-1-create-host-endpoints",children:"Step 1: Create host endpoints"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"#step-2-add-cidrs-to-deny-list-in-a-global-network-set",children:"Step 2: Add CIDRs to deny-list in a global network set"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"#step-3-create-deny-incoming-traffic-global-network-policy",children:"Step 3: Create deny incoming traffic global network policy"})}),"\n"]}),"\n",(0,o.jsx)(t.h3,{id:"best-practice",children:"Best practice"}),"\n",(0,o.jsx)(t.p,{children:"The following steps walk through the above required steps, assuming no prior configuration is in place. A best practice is to proactively do these steps before an attack (create the host endpoints, network policy, and global network set). In the event of a DoS attack, you can quickly respond by just adding the CIDRs that you want to deny-list to the global network set."}),"\n",(0,o.jsx)(t.h3,{id:"step-1-create-host-endpoints",children:"Step 1: Create host endpoints"}),"\n",(0,o.jsxs)(t.p,{children:["First, you create the HostEndpoints corresponding to the network interfaces where you want to enforce DoS mitigation rules. In the following example, the HostEndpoint secures the interface named ",(0,o.jsx)(t.strong,{children:"eth0"})," with IP ",(0,o.jsx)(t.strong,{children:"10.0.0.1"})," on node ",(0,o.jsx)(t.strong,{children:"jasper"}),"."]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: HostEndpoint\nmetadata:\n name: production-host\n labels:\n apply-dos-mitigation: 'true'\nspec:\n interfaceName: eth0\n node: jasper\n expectedIPs: ['10.0.0.1']\n"})}),"\n",(0,o.jsx)(t.h3,{id:"step-2-add-cidrs-to-deny-list-in-a-global-network-set",children:"Step 2: Add CIDRs to deny-list in a global network set"}),"\n",(0,o.jsxs)(t.p,{children:["Next, you create a Calico ",(0,o.jsx)(t.strong,{children:"GlobalNetworkset"}),", adding the CIDRs that you want to deny-list. In the following example, the global network set deny-lists the CIDR ranges ",(0,o.jsx)(t.strong,{children:"1.2.3.4/32"})," and ",(0,o.jsx)(t.strong,{children:"5.6.0.0/16"}),":"]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: GlobalNetworkSet\nmetadata:\n name: dos-mitigation\n labels:\n dos-deny-list: 'true'\nspec:\n nets:\n - '1.2.3.4/32'\n - '5.6.0.0/16'\n"})}),"\n",(0,o.jsx)(t.h3,{id:"step-3-create-deny-incoming-traffic-global-network-policy",children:"Step 3: Create deny incoming traffic global network policy"}),"\n",(0,o.jsxs)(t.p,{children:["Finally, create a Calico GlobalNetworkPolicy adding the GlobalNetworkSet label (",(0,o.jsx)(t.strong,{children:"dos-deny-list"})," in the previous step) as a selector to deny ingress traffic. To more quickly enforce the denial of forwarded traffic to the host at the packet level, use the ",(0,o.jsx)(t.strong,{children:"doNotTrack"})," and ",(0,o.jsx)(t.strong,{children:"applyOnForward"})," options."]}),"\n",(0,o.jsx)(t.pre,{children:(0,o.jsx)(t.code,{className:"language-yaml",children:"apiVersion: projectcalico.org/v3\nkind: GlobalNetworkPolicy\nmetadata:\n name: dos-mitigation\nspec:\n selector: apply-dos-mitigation == 'true'\n doNotTrack: true\n applyOnForward: true\n types:\n - Ingress\n ingress:\n - action: Deny\n source:\n selector: dos-deny-list == 'true'\n"})}),"\n",(0,o.jsx)(t.h2,{id:"additional-resources",children:"Additional resources"}),"\n",(0,o.jsxs)(t.ul,{children:["\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"/calico/3.29/reference/resources/globalnetworkset",children:"Global network sets"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"/calico/3.29/reference/resources/globalnetworkpolicy",children:"Global network policy"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"/calico/3.29/reference/resources/hostendpoint",children:"Create a host endpoint"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"https://www.iovisor.org/technology/xdp",children:"Introduction to XDP"})}),"\n",(0,o.jsx)(t.li,{children:(0,o.jsx)(t.a,{href:"https://prototype-kernel.readthedocs.io/en/latest/networking/XDP/index.html",children:"Advanced XDP documentation"})}),"\n"]})]})}function h(e={}){let{wrapper:t}={...(0,r.R)(),...e.components};return t?(0,o.jsx)(t,{...e,children:(0,o.jsx)(d,{...e})}):d(e)}},3413(e,t,n){n.d(t,{R:()=>s,x:()=>a});var i=n(16645);let o={},r=i.createContext(o);function s(e){let t=i.useContext(r);return i.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(o):e.components||o:s(e.components),i.createElement(r.Provider,{value:t},e.children)}}}]);
Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.