CONNLIMIT settings not obeyed by PS_LIMIT
Posted: 21 Apr 2014, 18:39
Hi,
there is an issue with CONNLIMIT and PS_LIMIT.
I have set:
CONNLIMIT = 80;20,2095;10
and under PORT SCAN TRACKING:
PS_LIMIT = 10
But blocks for CONNLIMIT are done at 10 and not at 20 on port 80 as specified, this is what LFD reports:
Time: Mon Apr 21 12:12:15 2014 -0500
IP: xx.xx.xx.xx (xx)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Apr 21 12:11:58 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 21 12:11:58 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 21 12:11:59 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
and so on...
Regards,
Sergio
there is an issue with CONNLIMIT and PS_LIMIT.
I have set:
CONNLIMIT = 80;20,2095;10
and under PORT SCAN TRACKING:
PS_LIMIT = 10
But blocks for CONNLIMIT are done at 10 and not at 20 on port 80 as specified, this is what LFD reports:
Time: Mon Apr 21 12:12:15 2014 -0500
IP: xx.xx.xx.xx (xx)
Hits: 11
Blocked: Temporary Block
Sample of block hits:
Apr 21 12:11:58 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 21 12:11:58 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
Apr 21 12:11:59 server1 kernel: Firewall: *ConnLimit* IN=eth1 OUT= MAC=xx.xx.xx.xx SRC=xx.xx.xx.xx DST=xx.xx.xx.xx LEN=60 TOS=0x00 PREC=0x00 TTL=49 ID=48773 PROTO=TCP SPT=15761 DPT=80 WINDOW=65535 RES=0x00 SYN URGP=0
and so on...
Regards,
Sergio