I'm not sure, but like I said, separate first by address and function. This could work a hundred different ways. I could give examples but they'd be off the top of my head and not properly designed.
I'm sure you could come up with a hundred different improperly designed ways off the top of your head. And it wouldn't work.
And trying to design it properly, you'd probably come to the conclusion that it won't work (without causing massive disruption and breaking everything we've built so far).
In many cases the only difference between a DDoS and normal operation is the volume of traffic at the victim host.