All of lore.kernel.org
 help / color / mirror / Atom feed
* max-src-conn-rate (Connection rate throttling per IP)
@ 2005-08-30 12:40 Benoit Panizzon
  2005-08-30 12:59 ` Jakub Wartak
                   ` (2 more replies)
  0 siblings, 3 replies; 5+ messages in thread
From: Benoit Panizzon @ 2005-08-30 12:40 UTC (permalink / raw)
  To: netfilter

[-- Attachment #1: Type: text/plain, Size: 1402 bytes --]

Hi all

I'm looking for a way to prevent connection DOSing of specific services.

The goal is to count the connection rate per conneting ip and then reject 
those connections if they pass a certain limit.

It looks like OpenBSD's pf is the only packet filter (except some commerctial 
Firewalls) which has this ability.

The best I managed with iptables is to throttle the connection rate for a 
specific port, but this of course affecs normal users trying to use that 
service and does not change the fact of the service being DOSed.

The other possibility I found is to write my own userspace QUEUE target 
connection rate tracker via the iptables api. But as I'm not a programmer and 
I think this is a quite common request I just wonder:

Hasn't allready somebody written such a per source connection rate limmiter?

Is there a repository of different userspace QUEUE tools where I could find 
something similar?

Regards
-- 
Benoît Panizzon, <bp@imp.ch>
------------------------------------------------------------------------
ImproWare AG, UNIXSP & ISP                   Phone:   +41 61 826 93 00
			     Kabelinternet-Hotline:   +41 61 826 93 07
Zurlindenstrasse 29                            Fax:   +41 61 826 93 01
CH-4133 Pratteln                               Net:   http://www.imp.ch/
------------------------------------------------------------------------

[-- Attachment #2: Type: application/pgp-signature, Size: 185 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2005-08-30 23:03 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2005-08-30 12:40 max-src-conn-rate (Connection rate throttling per IP) Benoit Panizzon
2005-08-30 12:59 ` Jakub Wartak
2005-08-30 13:03 ` Sascha Reissner
2005-08-30 23:03   ` Taylor, Grant
2005-08-30 13:07 ` Jakub Wartak

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.