My services were attacked by what appears to be a botnet of quite a large number of computers. Since all my servers have additional IPs, and my hosting provider lets me null-route my IP addresses to mitigate a DDoS attack by a single click in the web control panel on their site, I need some heads up on what are the steps for me to ensure that while the primary IP of a server is nulled, the server can be accessed via the other IP? Those are ubuntu servers.
Where do I configure the the additional IPs in Ubuntu?
Do I need to setup the additional IPs as "A" records in the DNS?
Any downtime expected when null-routing and is there anything more I need to do?
Regards!