Linux Netfilter discussions
 help / color / mirror / Atom feed
* question on rating SYN packets
@ 2003-02-07 22:01 Leonardo Rodrigues Magalhães
  2003-02-07 19:48 ` uniplex
  0 siblings, 1 reply; 4+ messages in thread
From: Leonardo Rodrigues Magalhães @ 2003-02-07 22:01 UTC (permalink / raw)
  To: netfilter ML


    Hello Guys,

    I'm trying to modify my script firewalls for not allowing a LOT of
connections being established on a specific port in a very small period of
time. I know I could easily do this using a rule like:

iptables -A INPUT -p tcp --dport XX -m state --state NEW -m limit --limit
Y/s -j ACCEPT


    Altough, with this rule, I would be globally limiting connections for
that specific port in Y connections per second. I would like to know if it's
possible building a rule that would allow, for example, 1 SYN packet per
second PER host. In this case, I wouldnt have a 'global' limit of SYN
packets. In fact, I would have a SYN limitation for EACH host.

    Question: is it possible for building a rule like this ? Is there any
filter on patch-o-matic tree that would allow this kind of rule ?


    Sincerily,
    Leonardo Rodrigues
    Soluções IP



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2003-02-08 19:23 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2003-02-07 22:01 question on rating SYN packets Leonardo Rodrigues Magalhães
2003-02-07 19:48 ` uniplex
2003-02-08 19:23   ` Leonardo Rodrigues Magalhães
2003-02-08 18:44     ` uniplex

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox