From mboxrd@z Thu Jan 1 00:00:00 1970 From: Georgi Alexandrov Subject: Re: tarpit before or after adding chain? Date: Sat, 17 Dec 2005 11:17:50 +0200 Message-ID: <43A3D7BE.5060201@gmail.com> References: <57F9959B46E0FA4D8BA88AEDFBE582900B59EA@pxtbenexd01.pxt.primeexalia.com> Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <57F9959B46E0FA4D8BA88AEDFBE582900B59EA@pxtbenexd01.pxt.primeexalia.com> List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: netfilter-bounces@lists.netfilter.org Errors-To: netfilter-bounces@lists.netfilter.org Content-Type: text/plain; charset="us-ascii"; format="flowed" To: netfilter@lists.netfilter.org Gary W. Smith wrote: >This should also work as well. We tarpit all data which should never >come through our firewalls. We also disabled tracking for the same. We >don't want the firewall wasting resources on this garbage. Another >trick that we do is we also dedicate a high/low IP for catching things >like SQL, HTTP, VNC, RDC, etc. This was things walking the network will >sometimes get hung, if they are not threaded. > > I don't think that his *one or two per day* cmd.exe automatic scans will get "through his firewall", or will "waste resources". Maybe filling your firewall with those useless rules will waste more resources? ;-) *Think again* (as seen in the national geographic channel) regards, Georgi Alexandrov