Gentoo Archives: gentoo-server

From: Miguel Sousa Filipe <miguel@×××××××××××.pt>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] syn cookies in real life
Date: Sat, 21 Aug 2004 10:28:47
Message-Id: 41272576.7070500@rnl.ist.utl.pt
In Reply to: [gentoo-server] syn cookies in real life by Kashani
1 Kashani wrote:
2
3 > I've been Googling for a few hours looking for information from
4 >anyone actually using syn cookies in a production system. We'd been hit
5 >with a few syn floods recently and were looking at a number of ways to
6 >stop them.
7 >
8 > From my research it appears that syn cookies should not affect the
9 >TCP session. There are some references to syn cookies causing slow downs
10 >with SMTP and ftp, but nothing really concrete. Also most of the info is
11 >from 2001 when 2.4 came out and syn cookies were linked with the newer
12 >iptables code. Was looking for case studies and hard stats.
13 >
14 > I'd like to hear from anyone running web server farms that has syn
15 >cookies turned on. Ideally you'd be pushing a fair amount of traffic or
16 >have 1k concurrent users per server at some point so I know it'll scale.
17 >Did you have any problems, weird firewalls blocking your servers, latency
18 >connection to the server, load balancers didn't like it, weird connections
19 >that hung around forever, and so forth.
20 >
21 >Thanks in advance,
22 >kashani
23 >
24 >
25 The only thing syn cookie will affect is the sistem itself and its
26 responsiveness to connections/sessions...
27 not other network equipment.. If i'm not missing something..
28
29 to the outside world, there is no diference, unless, accepting "known"
30 connections faster than unknown ones...
31 Latency connection should drop, since that is the purpose of syn cookies
32 (enhance performance on very high network connections, or DoSs)
33 about the load balancer... shouldn't have problems..since I never used
34 one... can only reason theoretically on this..
35 weird connections that would hung forever would seem like, syn cookie
36 support bug...
37
38 compliments,
39
40 --
41
42 Miguel Figueiredo Mascarenhas de Sousa Filipe
43 email: miguel@×××××××××××.pt (PORTUGAL)
44 http://mega.ist.utl.pt/~miguel
45
46 Equipa de Administração de Sistemas
47 Rede das Novas Licenciaturas (RNL)
48 Instituto Superior Técnico
49 http://www.rnl.ist.utl.pt
50 http://mega.ist.utl.pt