Hi
Few questions. Hope someone can help.
Let's say I have an incoming DDOS attack and I with bgp flowspec create a rule to rate-limit all udp from any to 1.0.0.1.
Where in the packet flow would this rate-limit occur? For example is it ingress on all interfaces or is it only egress on the interface towards 1.0.0.1?
Would the rate-limit occur after ingress sampling? (Will my flow collector see the traffic pre/post rate-limit)
Thank you