Automatic Block DNS floods?
Posted: 18 Aug 2010, 10:21
Hi Guys,
in my /var/log/messages i found lots of entry's (about 20 requests a second):
I've enabled "LF_BIND=100' but the flood keeps on going...
I've blocked another IP by hand yesterday but a new one started to flood me again.. I also can block this IP by hand, but could it also be done automaticly by CSF?
thanks!
Server is a Cent OS 5.4 with DirectAdmin installed
Linux Player.HOST 2.6.18-194.11.1.el5 #1 SMP Tue Aug 10 19:05:06 EDT 2010 x86_64 x86_64 x86_64 GNU/Linux
BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2
in my /var/log/messages i found lots of entry's (about 20 requests a second):
it turns out, somebody is dns flooding me, my server then generates lots of IO on my SAN which causes other servers to run a bit slower.Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#64048: query (cache) './NS/IN' denied
Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#32688: query (cache) './NS/IN' denied
Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#27528: query (cache) './NS/IN' denied
Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#26478: query (cache) './NS/IN' denied
Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#38763: query (cache) './NS/IN' denied
Aug 18 11:17:14 Player named[3706]: client 81.27.102.20#28586: query (cache) './NS/IN' denied
Aug 18 11:17:15 Player named[3706]: client 81.27.102.20#57290: query (cache) './NS/IN' denied
Aug 18 11:17:15 Player named[3706]: client 81.27.102.20#41726: query (cache) './NS/IN' denied
Aug 18 11:17:15 Player named[3706]: client 81.27.102.20#56843: query (cache) './NS/IN' denied
Aug 18 11:17:15 Player named[3706]: client 81.27.102.20#17108: query (cache) './NS/IN' denied
Aug 18 11:17:15 Player named[3706]: client 81.27.102.20#30559: query (cache) './NS/IN' denied
I've enabled "LF_BIND=100' but the flood keeps on going...
I've blocked another IP by hand yesterday but a new one started to flood me again.. I also can block this IP by hand, but could it also be done automaticly by CSF?
thanks!
Server is a Cent OS 5.4 with DirectAdmin installed
Linux Player.HOST 2.6.18-194.11.1.el5 #1 SMP Tue Aug 10 19:05:06 EDT 2010 x86_64 x86_64 x86_64 GNU/Linux
BIND 9.3.6-P1-RedHat-9.3.6-4.P1.el5_4.2