netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* DoS/DDoS protection for end nodes
@ 2024-04-17 19:43 William N.
  2024-04-17 20:25 ` Serg
  2024-04-17 20:47 ` Reindl Harald
  0 siblings, 2 replies; 15+ messages in thread
From: William N. @ 2024-04-17 19:43 UTC (permalink / raw)
  To: netfilter

Hi,

I have been searching and reading, and reading... I understand this is
a huge and complex subject, especially for a non-expert. I read earlier
discussions on this ML - some answers seem to say it is futile (i.e.
something that should be done by the ISPs, not by the end clients),
others suggest there is benefit in doing at least what is possible. So,
I hope to have some things clarified by the experts here.

XY: I am trying to do what is right for the network security of a SOHO
LAN. The nodes are distrusted, i.e. there is no assumption that they
are/will always be "clean" just because they are on the LAN.

My questions:

1. Is there a point to attempt DoS/DDoS protection directly on the LAN
nodes (Linux based)?

2. What is the right approach (using nftables)?

^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2024-04-22 17:32 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2024-04-17 19:43 DoS/DDoS protection for end nodes William N.
2024-04-17 20:25 ` Serg
2024-04-18 12:13   ` William N.
2024-04-18 14:11     ` Florian Kauer
2024-04-18 15:32       ` William N.
2024-04-18 16:16         ` Serhii
2024-04-18 16:31           ` William N.
2024-04-20 20:10         ` Kerin Millar
2024-04-21  9:10           ` William N.
2024-04-22 14:42         ` Quentin Deslandes
2024-04-22 15:12           ` William N.
2024-04-22 15:27             ` Quentin Deslandes
2024-04-22 17:32               ` William N.
2024-04-17 20:47 ` Reindl Harald
2024-04-17 21:24   ` Joshua Moore

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).