
My Network Was Destroyed.
Source: YouTube · Tubputers · published Aug 30, 2026 · 18:59
[BLUF]
After enduring relentless 900 Gbps DDoS attacks that saturated the network and triggered host-level nulling, the creator rebuilt the network topology with a specialized edge protection provider and redundant hardware to restore stability and scalability 9:23.
Key Takeaways:
• The initial failure was caused by a massive UDP flood that bypassed OVH’s mitigation, saturating the 10 Gbps uplink and forcing the host to cut all traffic to the origin 4:01.
• Previous theoretical fixes like separating UDP/TCP tunnels failed because the host provider ultimately nulls any origin under sustained attack strain, regardless of internal filtering 8:00.
• The new architecture routes traffic through a specialized edge protection provider, utilizing dual Juniper QFX switches with ASIC-based GRE encapsulation to ensure redundancy and reduce CPU load 10:34.
• The physical server room now features a spine-and-leaf switching architecture that allows for future expansion, including support for up to 16 leaf switches and multiple redundant database links 12:00.
• While the new system is stable, the creator identifies the single fiber cable from the ISP as the current remaining single point of failure, with plans to lay 24-core fiber for future load balancing 16:30.
[Closing statement]
This rebuild transforms a fragile, single-path network into a resilient, enterprise-grade infrastructure capable of handling significant traffic spikes and hardware failures. The experience highlights the critical importance of specialized DDoS mitigation and physical redundancy in modern hosting environments.
Sources:
- 0:00 The video begins with the network entirely destroyed due to ongoing attacks.
- 4:01 Explanation of the 900 Gbps UDP flood that saturated the 10 Gbps line.
- 8:00 Discussion of how the host provider nulls the origin to protect other services.
- 9:23 Introduction of the new network topology using an edge protection provider.
- 10:34 Details on using Juniper switches for ASIC-based GRE tunneling and redundancy.
- 12:00 Overview of the new spine-and-leaf architecture and its scalability limits.
- 16:30 Identification of the ISP fiber cable as the current single point of failure.
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
My network has been entirely destroyed, causing the entire network to go down. So, I came up with a couple plans. That's not very good, but in theory, it would work. What we'll find out [music] is that none of this in theory works. We got attacked regularly for weeks. I was in what we call in the trade deep Hey, and before you say anything, let me explain because I can already hear the comment section of this video screaming, "I told you so. I told you so. I told you so." But I want to imagine that there is a little bit more nuance to this situation. So, you read the title, you saw the thumbnail. My network has been entirely destroyed over the span of [music] the last few weeks. How you might be thinking, was it the multiple single points of failure you have repeatedly pointed out? No. Was…