From mboxrd@z Thu Jan 1 00:00:00 1970 From: Frank Smith Subject: Re: Connection Rate Limiting Date: Thu, 15 May 2003 11:31:24 -0500 Sender: netfilter-admin@lists.netfilter.org Message-ID: <43210000.1053016283@hoovers-59.hoovers.com> References: Mime-Version: 1.0 Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: Content-Disposition: inline Errors-To: netfilter-admin@lists.netfilter.org List-Help: List-Post: List-Subscribe: , List-Id: List-Unsubscribe: , List-Archive: Content-Type: text/plain; charset="us-ascii"; format="flowed" To: Daniel David Benson , netfilter@lists.netfilter.org I use this to rate-limit spiders: iptables -A FORWARD -p tcp -s xxx.xxx.xxx.xxx --dport 80 -m limit --limit 20/m -j ACCEPT Frank --On Thursday, May 15, 2003 08:58:25 -0700 Daniel David Benson wrote: > > Hopefully this one hasn't been answered before. We need to rate > limit on a per source IP address to port 80. We are seeing certain > web servers suffer from resource starvation under a DDOS attack. > The solution to this problem is rate limit the number of > connections any source IP address can make. Is this possible > to do with iptables? I have searched just about everything and > I can't seem to find anything. I know I can do traffic shaping > with iproute2, but I don't think that is the direction I want > to take. > > I know there is -limit in iptables, but unless I don't clearly > understand the implementation this limit is matched against > the resource and not on a per source. So, you have 5 source > IPs comming in with requests all of which effect the counters > global instead of each source having their own counter. > > We have tried mod_throttle for apache...but that crashes quite > a bit as the tables grow. Plus. I want to stop the attacks > before the apache level. > > Any help on this would be greatly appreciated. > > Thanks! > > -Dan > > -- Frank Smith fsmith@hoovers.com Systems Administrator Voice: 512-374-4673 Hoover's Online Fax: 512-374-4501