All of lore.kernel.org
 help / color / mirror / Atom feed
* Using -m limit to stop outbound portscanning viruses
@ 2005-02-05 22:37 Mike Ireton
  2005-02-05 22:49 ` R. DuFresne
  2005-02-05 22:50 ` Ramoni
  0 siblings, 2 replies; 5+ messages in thread
From: Mike Ireton @ 2005-02-05 22:37 UTC (permalink / raw)
  To: netfilter

Howdy list,

I'm concerned about portscanning viruses which have infected customer 
machines and are using all of that subscribers outbound to scan for 
(say) open port 445's all over the net. This isn't good for the wireless 
and tends to use up substantial resources in disproportion to the amount 
of data actually being moved. I have control over all my subscriber's 
CPE gear (running a custom embedded linux distro) and I am considering 
including an outbound firewalling feature to slow the rate at which new 
connections can be established. Basiclly, I want to ratelimit outbound 
syn's to some sane number (5/sec to start). I already have qos and 
bandwidth control in place at the cpe side, but this job is more 
'packets per second' oriented than 'bytes per second'.

I've looked at various cookbook examples of using '-m limit 5/s' and did 
rules like '-p tcp --tcp-flags SYN -m limit --limit 5/s -j DROP', but I 
effectively cut myself off and couldn't make any connections at all. 
Does anyone have a code snippet that could share which would do this job 
for me?

Thanks.



^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2005-02-05 23:51 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-02-05 22:37 Using -m limit to stop outbound portscanning viruses Mike Ireton
2005-02-05 22:49 ` R. DuFresne
2005-02-05 23:06   ` Mike Ireton
2005-02-05 23:51     ` R. DuFresne
2005-02-05 22:50 ` Ramoni

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.