From: "Derick Anderson" <danderson@vikus.com>
To: Spam User <spam@the-force.net>, netfilter@lists.netfilter.org
Subject: RE: stop accepting new connections on port 80
Date: Thu, 8 Dec 2005 08:50:29 -0500 [thread overview]
Message-ID: <FAC4E024BF776842876169173CE2F01313B3DB@mailbox.vikus.com> (raw)
> -----Original Message-----
> From: netfilter-bounces@lists.netfilter.org
> [mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of Spam User
> Sent: Wednesday, December 07, 2005 5:18 PM
> To: netfilter@lists.netfilter.org
> Subject: RE: stop accepting new connections on port 80
>
> >
> > I don't know exactly how you're determining the above: is it a long
> > download that gets killed? HTTP opens at least (and usually
> only) one
> > connection per page so the problem may be that the connection is
> > already closed even though the page is still being viewed.
> Unless you
> > are downloading something it's not likely your connection will last
> > much longer than four or five seconds on a heavily
> graphical page with
> > broadband.
>
>
> I had sort of thought about this, but then I thought thats
> what the related and established rules took care of.
>
> I suppose it it would be more helpful if the end goal was
> known.. to be more specific, I should have included that we
> use PHP sessions and what I'd like to do is keep the session
> open until all the currently open PHP sessions are closed
> (serve active session, don't accept new connections).
>
> I was hoping that the connection tracking would be associated
> to the sessions (not by session id or anything, but by the
> relationship of the established connections from the caller),
> so if user a looked at page X then 10 seconds later looked at
> page y, netfilter would know because that client had had
> established connections - I suppose I can see the flaws in
> that logic though. I thought that the callers connection
> info being in a time_wait state would possibly mean something
> to iptables.
Not knowing exactly how conntrack determines when a connection is
closing, I don't think I can help with explaining that. However each
page load is a different TCP connection (and the client may use a
different source port) so it would make sense to me that conntrack would
process it that way.
> I know this isnt an apache/php list, but maybe thats where I
> should be headed? Something like sending apache a usr1
> signal, but instead of accepting new connections with the new
> config, just don't accept new connections until the daemon is
> restarted.
>
> In any case, thanks for your speedy response.
>
If you can get your hands on the PHP, I'd start there. You could (a)
have PHP check for the existence of some flag file (say,
/var/.STOP_SESSIONs) and deny new sessions or (b) do that in the
database to cut down on I/O if you've got a busy server.
I don't know enough about the inner workings of Apache to suggest a
solution with that.
Derick Anderson
next reply other threads:[~2005-12-08 13:50 UTC|newest]
Thread overview: 8+ messages / expand[flat|nested] mbox.gz Atom feed top
2005-12-08 13:50 Derick Anderson [this message]
-- strict thread matches above, loose matches on Subject: below --
2005-12-07 21:58 stop accepting new connections on port 80 Derick Anderson
2005-12-07 22:18 ` Spam User
2005-12-07 20:38 Spam User
2005-12-09 18:42 ` Bill Hance
2005-12-09 19:08 ` R. DuFresne
2006-01-03 7:12 ` Jan Engelhardt
2005-12-14 20:33 ` Nick Drage
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=FAC4E024BF776842876169173CE2F01313B3DB@mailbox.vikus.com \
--to=danderson@vikus.com \
--cc=netfilter@lists.netfilter.org \
--cc=spam@the-force.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox