DDoS preparation is a combination of upstream capability, routing controls, monitoring, communications and rehearsed decision-making.
Typical scope
- Exposure and capacity review
- Upstream mitigation and scrubbing options
- RTBH and provider community design
- FlowSpec suitability and controls
- Detection thresholds and escalation
- Incident runbooks and post-incident evidence
Can a firewall stop a large DDoS attack?
Not when the attack saturates the internet circuit before traffic reaches the firewall. Effective design must involve upstream filtering or scrubbing before the constrained link.