SYN-FLOOD to LDAPS port from clients (was RE: Rapid Application)

Pete Nesbitt pete at linux1.ca
Mon May 31 03:11:17 UTC 2004


sory, forgot to rename the last post (sent as a Re: to Rapid App).

On May 29, 2004 01:59 pm, Ryan Golhar wrote:
> Sure, Here are my rules:
>
<snip...>
> # Syn flood filtering chain
>
> -A SYN-FLOOD -m limit --limit 1/s --limit-burst 4 -j RETURN
> -A SYN-FLOOD -j LOG --log-prefix "SYN-FLOOD: "
> -A SYN-FLOOD -j DROP
>
<snip...>
>
> -----
> Ryan Golhar
> Computational Biologist
> The Informatics Institute at
> The University of Medicine & Dentistry of NJ
>
> Phone: 973-972-5034
> Fax: 973-972-7412
> Email: golharam at umdnj.edu
>


hmm, I think this post is actually "SYN-FLOOD to LDAPS port from clients"

I don't see anything actually wrong, but a 1/sec limit seems a little tight, 
why not try increasing it and see what happens. Or what about 60/minute?

-- 
Pete Nesbitt, rhce





More information about the redhat-list mailing list