Global Load Balancing Lab (Interactive)
Race a regional outage through DNS TTL caches against a BGP prefix withdrawal, then diffuse a terabit attack across your PoPs. Compare failover latency and zombie-traffic exposure of Layer-7 GeoDNS routing versus Layer-3 BGP Anycast, including DDoS diffusion math.
GeoDNS vs BGP Anycast Failover Race
Layer-7 DNS steering obeys resolver caches; Layer-3 Anycast obeys BGP withdrawal timers.
How It Works Under the Hood
GeoDNS resolves clients to regional IPs using GeoIP and EDNS Client Subnet, but failover is hostage to caches: rogue ISP resolvers clamp even a 10-second TTL to 300-900 seconds, and OkHttp or URLSession keeps its own pools, so 30-50% of users keep hammering dead addresses for a quarter hour. BGP Anycast advertises one IP from every PoP, so a failure is a route withdrawal that global routers absorb in under a second — and the same property scatters a 1.5 Tbps attack across 300 PoPs at 5 Gbps each. The price is TCP flap risk during route changes, solved by Maglev/Katran consistent hashing and QUIC connection IDs.
Core Architectural Principles
- Effective failover time = max(your TTL, ISP clamp) for the cached share of users, per the TTL trap.
- Anycast failover is one BGP withdrawal; packets re-converge on the next-closest PoP in milliseconds.
- DDoS per PoP = attack Tbps ÷ PoP count — diffusion turns 1,500 Gbps into absorbable 12.5 Gbps streams.
Contrast the layers explicitly: GeoDNS is Layer 7 with minute-scale failover but rich policy (GDPR routing, canaries), Anycast is Layer 3 with sub-second withdrawal. Quantify one diffusion example and name QUIC connection IDs for BGP flap survival, and the global-ingress question is closed.
Anycast needs ASNs, owned /24 prefixes, and peering agreements plus shared connection state against route flaps, while GeoDNS stays cheaper and policy-flexible but cannot outrun the internet's DNS caches.