service information

Blackholing guide

Blackholing is typically used to fight massive DDoS attacks which congest the physical connection between DE-CIX and a customer router. A detailed description of how Blackholing works at DE-CIX is available here.

Besides signaling a blackhole via direct peering, you can signal blackholes via the route servers at all exchanges except Berlin and the Internet Exchanges in India and Russia. In addition, we offer dedicated Blackholing route servers in Frankfurt and Dubai.

Blackholing via direct peering

You have to set the corresponding next-hop manually (please see table below) when signaling a blackhole in a direct peering session.
Please also ask your peers to accept up to /32 for IPv4 and up to /128 for IPv6 from you to allow the service to work correctly.

Blackholing via the route servers

The re-distribution of BGP announcements by the Blackholing route server can be controlled in the same way as with the conventional route servers.

If you want to blackhole a certain IP prefix by using the conventional or Blackholing route servers, there are two ways of achieving this:

  • The BGP announcement carrying the IP prefix that should be blackholed is marked with the BLACKHOLE BGP Community (65535:666). Using the BLACKHOLE BGP Community is the recommended way of signaling a blackhole as it makes handling a lot easier.
  • The BGP announcement carrying the IP prefix that should be blackholed contains a pre-defined Blackhole IP address as next-hop. The table below lists the IPv4 and IPv6 Blackhole IP addresses for the different DE-CIX IXPs.
Internet ExchangeBlackhole next-hop IPv4 addressBlackhole next-hop IPv6 addressBGP BLACKHOLE community
Frankfurt 2001:7f8::1a27:66:95


Athens (SEECIX) 2001:7f8:f5::de1a:b:dead
Dubai (UAE-IX)
Johor Bahru103.119.235.662403:4ac0:2::953e:b:dead
Kuala Lumpur103.119.234.662403:4ac0:1::9532:b:dead
New York206.82.104.662001:504:36::f63a:63:34
Ruhr region (Ruhr-CIX)

Please do not set the NO-EXPORT or NO-ADVERTISE community on the BGP announcements marked as blackhole as this tells the route servers to not re-distribute this announcement.

Configuration examples of how to setup a BGP session to the Blackholing route server can be found in the route server guides.

Blackholing via the dedicated Blackholing route servers

In Frankfurt and Dubai (UAE-IX), we operate dedicated Blackholing route servers. The idea behind providing a Blackholing route server is that some router vendors do not support the acceptance of /32 (IPv4) or /128 (IPv6) BGP announcement depending on the availability of the Blackhole BGP community or a particular next hop. With a specific Blackholing route server peers can (and should) accept /32 (IPv4) or /128 (IPv6) announcements from this route server without having to change the BGP connection to conventional route servers.

The Blackholing route server consists of one machine. The software utilized to provide the Blackholing route server service is BIRD.

The Blackholing route server is connected to the conventional route server system. All BGP announcements that are marked as Blackholes (e.g. by rewriting the next hop to the pre-defined Blackholing IP address or by tagging the BGP announcement with the Blackhole BGP Community) received by the conventional route server system or a Blackholing route server are automatically redistributed to the other route server system.

If the Blackholing route server receives a BGP announcement marked as a blackhole, the NO-EXPORT community and the BLACKHOLE community are added if these communities are not already available. This makes sure each BGP announcement marked 'Blackhole' can be easily filtered and does not spread widely in the Internet routing system.

The Blackholing route server accepts only BGP announcements marked as blackholes. If a BGP announcement is not marked as a blackhole, the announcement is rejected. The reason for this is that DE-CIX wants to make sure that no blackholes are triggered if BGP announcementy are leaked to the Blackholing route server by accident.

Feature Matrix

The following matrix summaries the Blackholing features available at the conventional and Blackholing Route Server systems:

Support for Blackholing

BLACKHOLE BGP community support for signaling a blackhole

Automatic BGP next-hop rewrite to pre-defined blackhole IP for BGP announcements marked as blackholes

Dedicated BGP session for blackhole announcements: restrict your filters to blackholes only and safely accept up to /32 (IPv4) and /128 (IPv6)

Available at DE-CIX Frankfurt and UAE-IX

Available at DE-CIX IXPs except Frankfurt and UAE-IX Dubai