RE: DOS attack tracing

Yes, the 7206vxr with whatever processor really checks out when under
any kind of real flood through it. It's big brother, the 7304-NSE100
does as well. But the 7304-NPE100 with the PXF can forward that (d)DoS
very well. Even with fairly extensive ingress filters. The kick in the
head is that the processors are the same price. I don't know why they
even sell the NPE100...

Then you can take whatever measures you like to characterize and
mitigate. A combination of upstream null routing (poisoning
communities), ingress filters, core null routing, and your favorite ddos
mitigation equipment filtering has been very effective for us.