syn block feature
Posted: 23 Oct 2007, 23:16
I been using a modifed version of dos deflate to block connections with so many syn_recv but its not perfect. Only can run every minute and havent really made a viable unban feature.
If there was a thing on csf like connection tracking that parsed netstat for so many syn_recv connections per ip and ban the ones with the limit, I usually do 10 but sometimes it can ban legit users.
And make it where you can run every 30 seconds or something. This would be an awesome feature on csf and would help greatly dealing with ddos.
If there was a thing on csf like connection tracking that parsed netstat for so many syn_recv connections per ip and ban the ones with the limit, I usually do 10 but sometimes it can ban legit users.
And make it where you can run every 30 seconds or something. This would be an awesome feature on csf and would help greatly dealing with ddos.