Re: use of -m limit for Syn Flood protection

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Jiann-Ming Su wrote:
If you're trying to limit the SYNs to 4/sec, then the --limit should
be "--limit 4/s" along with the --limit-burst 4.  Though, 4 SYNs per
second is hardly a syn flood.  Also, you may want to specify the
destination port of the syn flood to give more grainular control.

Hi Jiann

Thank you for your reply.

May I ask what you would consider a more realistic limit /value.

I currently have ports 25, 80 and 443 open. I would like to strive to get a respectable value that would cater for these ports.

Kind Regards
Brent Clark



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux