From: Kevin Turner <acapnotic@users.sourceforge.net>
To: lartc@vger.kernel.org
Subject: [LARTC] Re: ingress policing
Date: Fri, 06 Apr 2001 03:01:11 +0000 [thread overview]
Message-ID: <marc-lartc-98652611217566@msgid-missing> (raw)
On Thu, Apr 05, 2001 at 11:59:43PM +0200, Guy Van Den Bergh wrote:
> One major application of ingress policing is only letting a limited
> rate of icmp or tcp syn packets coming into your network. That will
> keep your network less vulnerable for ping floods and dos attacks.
It's perhaps worth noting that for applications like this, in which you
don't want to queue the traffic at all but just drop or reject it, this
can be easily done with kernel 2.4's netfilter, using iptables and
LIMIT. This is covered in Rusty's Remarklably Useful but Allegedly
Unreliable Guide, the Linux 2.4 Packet Filtering HOWTO at
http://netfilter.kernelnotes.org/
_______________________________________________
LARTC mailing list / LARTC@mailman.ds9a.nl
http://mailman.ds9a.nl/mailman/listinfo/lartc HOWTO: http://ds9a.nl/2.4Routing/
reply other threads:[~2001-04-06 3:01 UTC|newest]
Thread overview: [no followups] expand[flat|nested] mbox.gz Atom feed
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=marc-lartc-98652611217566@msgid-missing \
--to=acapnotic@users.sourceforge.net \
--cc=lartc@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox