Re: [SLE] Firewall is getting hammered...help

From: js (fyrbrds_at_netscape.net)
Date: 09/29/03

  • Next message: Frits Wüthrich: "Re: [SLE] Holding Linux back in pieces"
    Date: Mon, 29 Sep 2003 22:55:19 +0200
    To: "suse-linux-e@suse.com" <suse-linux-e@suse.com>
    
    

    gary wrote:

    >
    > from the C/L
    >
    > iptables -A INPUT -s worse.IP.Addresses -d 0/0 --proto all -j DROP
    >
    > set it, and forget it.
    >
    >

    This will only help him so much. Those packets will still keep hitting
    his firewall and taking up processing time and bandwidth. It will keep
    the packets from clogging up his internal network, but will do nothing
    for internal-to-external throughput. If you are getting so many that
    your external bandwidth is being eaten up you should contact your isp
    and have them track the main offenders to their sources because this
    would most likely be a coordinated DOS attack. 10,000 a day won't
    qualify, since depending on your config you might get that many per
    second in *real* DOS attack, but you have to decide what is cripling for
    your network.

    JS

    -- 
    Check the headers for your unsubscription address
    For additional commands send e-mail to suse-linux-e-help@suse.com
    Also check the archives at http://lists.suse.com
    Please read the FAQs: suse-linux-e-faq@suse.com
    

  • Next message: Frits Wüthrich: "Re: [SLE] Holding Linux back in pieces"

    Relevant Pages

    • Re: Cant use internal network after dialup modem is used -- FOLLOWUP: better output
      ... Here is a corrected/improved version with more useful indenting. ... Just after reboot, can use internal network. ... In particular, during and after use of dialup modem, ping gives: ... packets transmitted, 4 packets received, 0% packet loss ...
      (comp.os.linux.setup)
    • Re: Iptables or misconfiguration?
      ... > I'm building up a router with IPTABLES. ... > communicates with the machines on the internal network, ... These addresses should never appear as sources on any packets you receive ... to attack others. ...
      (comp.unix.admin)
    • Re: Odd windows ICMP... any ideas what this is?
      ... > Our IDS has been reporting some large ICMP packets on ... > our internal network. ... Apparently w32 boxes ping their domain controller regularly. ... profiling the ICMP traffic immediately afterwards would help to provide ...
      (Incidents)
    • IPFW questions
      ... I'm in the process of reviewing my IPFW firewall rules since they've ... bdg_forward packets. ... that when a machine on my internal network transmits a packet that is ...
      (comp.unix.bsd.freebsd.misc)
    • Re: IPFilter/IPNat and rdr
      ... but the next rule overrides lets the packet in IF it is ... You may or may not want the quick keyword in that second rule, ... > rule to prevent packets from the outside that contain a destination IP ... > on my internal network from passing through my firewall and entering my ...
      (FreeBSD-Security)