From: Markus Feldmann <feldmann_markus@gmx.de>
To: netfilter@vger.kernel.org
Subject: Re: iptables NEW or SYN
Date: Thu, 13 May 2010 22:55:12 +0200 [thread overview]
Message-ID: <hshovg$o7e$1@dough.gmane.org> (raw)
In-Reply-To: <4BEC5C6C.1010704@plouf.fr.eu.org>
Pascal Hambourg schrieb:
>
> It depends on your needs.
The state NEW doesn't work for my apache server, only the --syn flag. It
seems that many packets on my server wouldn't catched from the NEW rule,
because my server thinks they are not NEW. The clients still want to
establish a connection, but my server only let NEW packets in. If some
of my frineds want to connect several times, or when the first packet
doesn't fit up with my rules. Then they fall in my blacklist and i got
problems. :-(
So it is better to set up a rule with the --syn argument combined with
the hashlimit extension, to be save against syn flood attacks.
What do you think?
regards markus
next prev parent reply other threads:[~2010-05-13 20:55 UTC|newest]
Thread overview: 20+ messages / expand[flat|nested] mbox.gz Atom feed top
2010-05-13 17:08 iptables NEW or SYN Markus Feldmann
2010-05-13 17:18 ` Jan Engelhardt
2010-05-13 17:42 ` Markus Feldmann
2010-05-13 18:00 ` Markus Feldmann
2010-05-13 18:09 ` Markus Feldmann
2010-05-13 20:09 ` Pascal Hambourg
2010-05-13 20:55 ` Markus Feldmann [this message]
2010-05-13 18:05 ` Markus Feldmann
2010-05-13 18:19 ` Curby
2010-05-13 18:45 ` Markus Feldmann
2010-05-13 19:23 ` Mistick Levi
2010-05-13 21:45 ` Markus Feldmann
2010-05-13 22:46 ` Curby
2010-05-14 0:06 ` Markus Feldmann
2010-05-14 0:23 ` Markus Feldmann
2010-05-14 2:19 ` Markus Feldmann
2010-05-14 6:41 ` Jan Engelhardt
2010-05-14 12:16 ` Markus Feldmann
2010-05-14 5:08 ` Mart Frauenlob
[not found] <hsgu5c$d8c$1@dough.gmane.org>
2010-05-13 15:21 ` ratheesh k
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to='hshovg$o7e$1@dough.gmane.org' \
--to=feldmann_markus@gmx.de \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).