netfilter-devel.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* 6to4/Teredo IPv4 matching
@ 2010-12-14 14:40 Luke-Jr
  2010-12-14 20:29 ` Jozsef Kadlecsik
  0 siblings, 1 reply; 2+ messages in thread
From: Luke-Jr @ 2010-12-14 14:40 UTC (permalink / raw)
  To: Jozsef Kadlecsik; +Cc: linux-kernel@vger.kernel.org, netfilter-devel

Are there any plans to allow matching 6to4/Teredo IPv6 packets against IPv4 
rules (or at least ipsets)? Recently I have a server that's been under 
constant DDoS from China, and I found that when I use ipsets to drop 
everything from China, some continue to hammer my server over 6to4 and/or 
Teredo. So I just figured I'd throw the idea out there in case it hasn't 
occurred to anyone yet. ;)

^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: 6to4/Teredo IPv4 matching
  2010-12-14 14:40 6to4/Teredo IPv4 matching Luke-Jr
@ 2010-12-14 20:29 ` Jozsef Kadlecsik
  0 siblings, 0 replies; 2+ messages in thread
From: Jozsef Kadlecsik @ 2010-12-14 20:29 UTC (permalink / raw)
  To: Luke-Jr; +Cc: linux-kernel@vger.kernel.org, netfilter-devel

Hi,

On Tue, 14 Dec 2010, Luke-Jr wrote:

> Are there any plans to allow matching 6to4/Teredo IPv6 packets against IPv4 
> rules (or at least ipsets)? Recently I have a server that's been under 
> constant DDoS from China, and I found that when I use ipsets to drop 
> everything from China, some continue to hammer my server over 6to4 and/or 
> Teredo. So I just figured I'd throw the idea out there in case it hasn't 
> occurred to anyone yet. ;)

ipset 5 is about to be released in this week, with both IPv4 and IPv6 
support. But feeding the sets with the proper addresses/networks is left 
to the users :-).

Best regards,
Jozsef
-
E-mail  : kadlec@blackhole.kfki.hu, kadlec@mail.kfki.hu
PGP key : http://www.kfki.hu/~kadlec/pgp_public_key.txt
Address : KFKI Research Institute for Particle and Nuclear Physics
          H-1525 Budapest 114, POB. 49, Hungary

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2010-12-14 20:29 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2010-12-14 14:40 6to4/Teredo IPv4 matching Luke-Jr
2010-12-14 20:29 ` Jozsef Kadlecsik

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).