From mboxrd@z Thu Jan 1 00:00:00 1970 From: Pasi =?iso-8859-1?Q?K=E4rkk=E4inen?= Subject: Re: Protecting against DoS Date: Wed, 10 Dec 2003 18:53:06 +0200 Sender: netfilter-admin@lists.netfilter.org Message-ID: <20031210165306.GH17221@edu.joroinen.fi> References: <20031209154333.GB17221@edu.joroinen.fi> <20031209090221.413b7286.mgale@utilitran.com> <20031209162820.GC17221@edu.joroinen.fi> <20031209094047.4dbb09f9.mgale@utilitran.com> <20031209165146.GD17221@edu.joroinen.fi> <20031209100650.485e8a4f.mgale@utilitran.com> <20031209171322.GE17221@edu.joroinen.fi> Mime-Version: 1.0 Content-Transfer-Encoding: quoted-printable Return-path: Content-Disposition: inline In-Reply-To: <20031209171322.GE17221@edu.joroinen.fi> Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="iso-8859-1" To: Michael Gale Cc: netfilter@lists.netfilter.org On Tue, Dec 09, 2003 at 07:13:22PM +0200, Pasi K=E4rkk=E4inen wrote: > On Tue, Dec 09, 2003 at 10:06:50AM -0700, Michael Gale wrote: > > Hello, > >=20 > > You could try using a rate limit -- you could allow a machine to make = lets say 10 outbound=20 > > connections a second and then ... > >=20 > > Depending on your network policy you could drop or log all other outbou= nd request. > >=20 >=20 > This is what I'm planning to do.. and this is also the reason I was asking > the questions in the original mail :-) >=20 If you have some facts/suggestions, please comment my original questions.. = Thanks! -- Pasi K=E4rkk=E4inen =20 ^ . . Linux / - \ Choice.of.the .Next.Generation.