Blackholing Service

To mitigate DDoS attack, CXC provide a blackhole next-hop address for both IPv4 and IPv6 address-families. These next-hop addresses will resolves (via ARP/ND) to a predefined blackhole MAC address, which will be dropped by our switch port ingress filter where members are directly connected and thereby preventing DDoS traffic from reaching its destination. CXC blackholing (BH) service is available on our Route Servers (RS) and members are encouraged to participate.

Below table contain CXC blackhole next-hop address and BGP BLACKHOLE community information.

ClusterIPv4 AddressIPv6 AddressIPv6 Link-Local AddressMac AddressBLACKHOLE Community
Denpasar103.225.171.62400:9c80:0:171::666fe80::dcad:beff:feef:1666de:ad:be:ef:16:6665535:666
Jakarta103.225.172.662400:9c80:0:173::172:666fe80::dcad:beff:feef:2666de:ad:be:ef:26:6665535:666
Blackholing via Route Server (RS)

Below are guideline and restrictions when using blackholing service via RS:

Open Internet Exchange
APIX
APIX
Peering DB
Peering DB