Revision history for IPTablesRulesToBlockDDOSTraffic


Revision [3140]

Last edited on 2013-11-26 06:40:08 by alex24
Additions:
[[IPTablesRulesToBlockDDOSTrafficES EspaƱol]]


Revision [2960]

Edited on 2012-11-23 10:20:00 by JeffTaylor [Added Shorewall rules]
Additions:
Shorewall users may enter the following lines in their 'rules' file to perform the same rate limiting:
DNS(ACCEPT) net $FW ;rate=s:DNSTHROTTLE:30/min:10
DNS(DROP) net $FW
These two lines should be placed //before// any other DNS accept rules. The second line only drops those packets that fall outside of the rate limits. As above, this rule allows up to 30 packets per minute from an IP address, with a burst of 10 packets.
Deletions:
I believe Jeff is going to follow up this email with equivalent
shorewall rules. Please report back with successes and/or failures.
I'm sure the parameters I've chosen can use much more tweaking.


Revision [2957]

The oldest known version of this page was created on 2012-10-18 09:44:50 by BrianKoontz [Added Shorewall rules]
Valid XHTML :: Valid CSS: :: Powered by WikkaWiki