Re: Hammer protection

Linux Advanced Routing and Traffic Control

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



hi Joachim,

> I want to deny a user who has just logged off .. for about
> 10seconds.
I think you can only limit the number of syn-pakets like you already
proposed.

> I tried with this, but that didn't work. Maybe my mind is going
> completely in the wrong direction today? =)
> 
> iptables -I INPUT -i eth0 -p tcp -s 0/0 -d $my_ip --dport 21 -m
> limit --limit 10/second --limit-burst 1 --tcp-flags ALL SYN -j
> ACCEPT
I'm not sure, but I think you just mixed the parameters up. --limit
10/second allows 10 SYN pakets per second so if you only want one
paket per 10 seconds you should perhaps try 6/minute or maybe say
1/minute and set the limit-bust to 3 or so.

best regards
		Sebastian

-- 
Sebastian 'spax' Pape          | I'm like time ... u can't stop me!  
mailto: sebastian@p-a-p-e.de   | 
gpg: http://p-a-p-e.de/gpg.asc | 
         --- Do you want to know more? http://www.p-a-p-e.de/ ---


_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://lartc.org/

[Index of Archives]     [LARTC Home Page]     [Netfilter]     [Netfilter Development]     [Network Development]     [Bugtraq]     [GCC Help]     [Yosemite News]     [Linux Kernel]     [Fedora Users]
  Powered by Linux