SYN-FLOOD to LDAPS port from clients (was RE: Rapid Application)
Pete Nesbitt
pete at linux1.ca
Mon May 31 03:11:17 UTC 2004
sory, forgot to rename the last post (sent as a Re: to Rapid App).
On May 29, 2004 01:59 pm, Ryan Golhar wrote:
> Sure, Here are my rules:
>
<snip...>
> # Syn flood filtering chain
>
> -A SYN-FLOOD -m limit --limit 1/s --limit-burst 4 -j RETURN
> -A SYN-FLOOD -j LOG --log-prefix "SYN-FLOOD: "
> -A SYN-FLOOD -j DROP
>
<snip...>
>
> -----
> Ryan Golhar
> Computational Biologist
> The Informatics Institute at
> The University of Medicine & Dentistry of NJ
>
> Phone: 973-972-5034
> Fax: 973-972-7412
> Email: golharam at umdnj.edu
>
hmm, I think this post is actually "SYN-FLOOD to LDAPS port from clients"
I don't see anything actually wrong, but a 1/sec limit seems a little tight,
why not try increasing it and see what happens. Or what about 60/minute?
--
Pete Nesbitt, rhce
More information about the redhat-list
mailing list