Linux Netfilter discussions
 help / color / mirror / Atom feed
From: "Derick Anderson" <danderson@vikus.com>
To: Spam User <spam@the-force.net>, netfilter@lists.netfilter.org
Subject: RE: stop accepting new connections on port 80
Date: Thu, 8 Dec 2005 08:50:29 -0500	[thread overview]
Message-ID: <FAC4E024BF776842876169173CE2F01313B3DB@mailbox.vikus.com> (raw)

 

> -----Original Message-----
> From: netfilter-bounces@lists.netfilter.org 
> [mailto:netfilter-bounces@lists.netfilter.org] On Behalf Of Spam User
> Sent: Wednesday, December 07, 2005 5:18 PM
> To: netfilter@lists.netfilter.org
> Subject: RE: stop accepting new connections on port 80
> 
> >
> > I don't know exactly how you're determining the above: is it a long 
> > download that gets killed? HTTP opens at least (and usually 
> only) one 
> > connection per page so the problem may be that the connection is 
> > already closed even though the page is still being viewed. 
> Unless you 
> > are downloading something it's not likely your connection will last 
> > much longer than four or five seconds on a heavily 
> graphical page with 
> > broadband.
> 
> 
> I had sort of thought about this, but then I thought thats 
> what the related and established rules took care of.
> 
> I suppose it it would be more helpful if the end goal was 
> known.. to be more specific, I should have included that we 
> use PHP sessions and what I'd like to do is keep the session 
> open until all the currently open PHP sessions are closed 
> (serve active session, don't accept new connections).
> 
> I was hoping that the connection tracking would be associated 
> to the sessions (not by session id or anything, but by the 
> relationship of the established connections from the caller), 
> so if user a looked at page X then 10 seconds later looked at 
> page y, netfilter would know because that client had had 
> established connections - I suppose I can see the flaws in 
> that logic though.  I thought that the callers connection 
> info being in a time_wait state would possibly mean something 
> to iptables.

Not knowing exactly how conntrack determines when a connection is
closing, I don't think I can help with explaining that. However each
page load is a different TCP connection (and the client may use a
different source port) so it would make sense to me that conntrack would
process it that way.

> I know this isnt an apache/php list, but maybe thats where I 
> should be headed?  Something like sending apache a usr1 
> signal, but instead of accepting new connections with the new 
> config, just don't accept new connections until the daemon is 
> restarted.
> 
> In any case, thanks for your speedy response.
> 

If you can get your hands on the PHP, I'd start there. You could (a)
have PHP check for the existence of some flag file (say,
/var/.STOP_SESSIONs) and deny new sessions or (b) do that in the
database to cut down on I/O if you've got a busy server.

I don't know enough about the inner workings of Apache to suggest a
solution with that.

Derick Anderson 


             reply	other threads:[~2005-12-08 13:50 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2005-12-08 13:50 Derick Anderson [this message]
  -- strict thread matches above, loose matches on Subject: below --
2005-12-07 21:58 stop accepting new connections on port 80 Derick Anderson
2005-12-07 22:18 ` Spam User
2005-12-07 20:38 Spam User
2005-12-09 18:42 ` Bill Hance
2005-12-09 19:08   ` R. DuFresne
2006-01-03  7:12   ` Jan Engelhardt
2005-12-14 20:33 ` Nick Drage

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=FAC4E024BF776842876169173CE2F01313B3DB@mailbox.vikus.com \
    --to=danderson@vikus.com \
    --cc=netfilter@lists.netfilter.org \
    --cc=spam@the-force.net \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox