RTBH blackholes
Remotely triggered blackholes, without the manual work
When an attack is bigger than your links, or FlowSpec isn't an option, Heimnull announces the attacked /32 or /128 to your routers over BGP with your blackhole community. They drop the traffic to that address, and Heimnull withdraws the route when the attack is over.
# What one iBGP session receives (example) 203.0.113.10/32 next hop 192.0.2.254 # discard next hop communities 65535:666 # RFC 7999 local-pref 200 # iBGP only 2001:db8:42::10/128 next hop 2001:db8::ffff # IPv6 next hop communities 65535:666
How it works
Detected
A host goes over one of its hostgroup's limits for three evaluations in a row: bits, packets, SYN, fragments, amplification or ICMP, each measured every second.
Announced
Heimnull's BGP speaker sends the host route to every session set to receive blackholes, with your communities and each session's own next hop. Your routers send the traffic to discard.
Withdrawn
After the ban's duration, 15 minutes by default, unless the attack is still going: then it's extended, up to a maximum of a day. Or withdraw it as soon as the attack ends.
Your communities, your next hops
Communities
Standard, large and extended communities, several of each, set once and overridden per hostgroup. RFC 7999's BLACKHOLE community, 65535:666, is the default we recommend.
Next hops
One per session and per address family, pointing at a discard route on the router. Or leave it empty and set the discard next hop in the router's import policy.
Route attributes
Local preference for iBGP sessions and an optional MED. Each session can receive blackholes, FlowSpec or both, for IPv4, IPv6 or both.
Repeat attacks and upstream blackholing
Repeat attacks. Each earlier ban of the same address in the last 24 hours doubles the next one's duration, up to the maximum, so an attacker who comes back every 15 minutes doesn't get the address back every 15 minutes.
Upstream RTBH. Your edge routers can pass the host route on to your transit providers with their blackhole community, so the attack is dropped before it reaches your links. Then your routers stop seeing it, and the attack looks over when it isn't. Heimnull handles this at expiry: it withdraws the route, keeps watching, and blackholes the address again straight away, for longer, if the attack is still there.
FlowSpec first, blackhole if needed
A blackhole takes the address offline for as long as it lasts. That's often the right trade when an attack fills your uplinks, but a FlowSpec rule can drop just the attack. Each hostgroup chooses one of four actions:
| Action | What happens |
|---|---|
| Notify | Record the attack and send alerts. The default for every hostgroup. |
| FlowSpec | Announce a rule built from the attack's fingerprint. |
| Blackhole | Announce the host route with your blackhole community. |
| FlowSpec, escalating to a blackhole | Start with a rule, and add a blackhole if the attack stays above a set rate for the escalation delay. |
Guard rails
- Host routes in your networks only. A blackhole is a /32 or /128 inside your own address space, unless you allow aggregates for a hostgroup.
- Never a whitelisted address. A blackhole can't cover any address on the whitelist.
- A community is required. A blackhole without one is refused, because the router couldn't tell it apart.
- Families kept apart. IPv4 routes only with IPv4 next hops, IPv6 with IPv6.
- A cap and a stop button. At most 100 active bans by default, and an emergency withdraw-all that holds until an admin resumes.
- Dry run and preview. See what each session would get, or run a hostgroup in dry-run mode before it announces for real.
- Re-checked every 30 seconds. The routes in BGP are compared with the bans Heimnull holds, and a ban that no longer passes the checks is withdrawn.
- Every refusal recorded. In the audit log, with a notification, and the reason.
We also recommend a filter on the router that accepts only host routes inside your networks with the blackhole community, so the router stays safe even if Heimnull is misconfigured.
Router support
Any router that takes routes over BGP can act on a blackhole. Setup guides cover the Juniper MX and MikroTik RouterOS 7.
On the MX, the import policy accepts only host routes inside your networks that carry the community, and sends them to discard. On MikroTik, a routing filter does the same and marks the route as a blackhole.
/* Juniper MX: accept only Heimnull's host routes with the community */
policy-options {
community heimnull-blackhole members 65535:666;
policy-statement heimnull-in {
term blackhole-v4 {
from {
family inet;
community heimnull-blackhole;
route-filter 203.0.113.0/24 prefix-length-range /32-/32;
}
then { next-hop discard; accept; }
}
term reject-rest {
then reject;
}
}
}Example prefix. Add a matching IPv6 term for /128 routes, and check against the documentation for your Junos release.
Questions
What is RTBH?
Remotely triggered blackholing: a BGP route for the attacked address, tagged with a community, tells your routers (and optionally your transit providers) to drop all traffic to it. It protects the rest of your network and your links at the cost of the one address.
Does a blackhole take the host offline?
Yes, for the length of the ban. That's why many networks start with FlowSpec and escalate to a blackhole only when the rule isn't enough.
Can I blackhole an address by hand?
Yes. Mitigations → “Mitigate an address” takes the address and a reason, shows the preview, and goes through the same checks as automatic bans.
What about attacks across a whole prefix?
That's carpet bombing. Aggregate blackholes are off by default and need an explicit switch per hostgroup, a confirmation, and a minimum prefix length: /24 for IPv4 and /48 for IPv6 by default.
Related
See it on real traffic
The demo runs the full console on made-up traffic, with attacks and mitigations to click through. To try Heimnull on your own network, write to us.
info@heimnull.com