What rules should be set with iptables to block syn attacks and still allow legitimate traffic? The machine that I'm talking about is a squid cache server with about 200 clients which also acts as a router with NAT for one box on the private LAN. I did tried several approaches but it seems that the rules also interfere with client-to-squid connections. Any thoughts on that? Thanks! Alex -- redhat-list mailing list unsubscribe mailto:redhat-list-request@xxxxxxxxxx?subject=unsubscribe https://www.redhat.com/mailman/listinfo/redhat-list