Linux Netfilter discussions
 help / color / mirror / Atom feed
* how to block 10000's of addresses?
@ 2002-10-13 11:50 Phil Howard
  2002-10-13 12:10 ` Antony Stone
                   ` (2 more replies)
  0 siblings, 3 replies; 15+ messages in thread
From: Phil Howard @ 2002-10-13 11:50 UTC (permalink / raw)
  To: netfilter

I would like to know how best to block 10000's of addresses using
netfilter.  Clearly I do not want to be placing 10000's of individual
filter table entries in.  Is there some kind of means to set up the
equivalent of a routing table like lookup structure (which can be
added to and removed from separately) which a single netfilter rule
would reference to apply matches?

I want to block _incoming_ packets.  Null routing these addresses is
not sufficient, as the lame SYNs will continue to eat up resources.

-- 
-----------------------------------------------------------------
| Phil Howard - KA9WGN |   Dallas   | http://linuxhomepage.com/ |
| phil-nospam@ipal.net | Texas, USA | http://ka9wgn.ham.org/    |
-----------------------------------------------------------------


^ permalink raw reply	[flat|nested] 15+ messages in thread

end of thread, other threads:[~2002-10-13 22:05 UTC | newest]

Thread overview: 15+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2002-10-13 11:50 how to block 10000's of addresses? Phil Howard
2002-10-13 12:10 ` Antony Stone
2002-10-13 13:00   ` Phil Howard
2002-10-13 13:13     ` Thomas Lussnig
2002-10-13 13:45       ` Phil Howard
2002-10-13 13:47     ` Robert P. J. Day
2002-10-13 14:56       ` Phil Howard
2002-10-13 16:25         ` Robert P. J. Day
2002-10-13 22:05           ` Phil Howard
2002-10-13 13:53     ` Antony Stone
2002-10-13 15:10       ` Phil Howard
2002-10-13 15:41         ` Antony Stone
2002-10-13 16:40           ` Thomas Lussnig
2002-10-13 17:25 ` Thomas Heinz
2002-10-13 17:42 ` Thomas Heinz

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox