Gentoo Archives: gentoo-server

From: Kashani <kashani-list@××××××××.net>
To: gentoo-server@l.g.o
Subject: [gentoo-server] syn cookies in real life
Date: Fri, 13 Aug 2004 06:52:16
Message-Id: Pine.LNX.4.56L0.0408122342070.4157@bandwidth.zanti.com
1 I've been Googling for a few hours looking for information from
2 anyone actually using syn cookies in a production system. We'd been hit
3 with a few syn floods recently and were looking at a number of ways to
4 stop them.
5
6 From my research it appears that syn cookies should not affect the
7 TCP session. There are some references to syn cookies causing slow downs
8 with SMTP and ftp, but nothing really concrete. Also most of the info is
9 from 2001 when 2.4 came out and syn cookies were linked with the newer
10 iptables code. Was looking for case studies and hard stats.
11
12 I'd like to hear from anyone running web server farms that has syn
13 cookies turned on. Ideally you'd be pushing a fair amount of traffic or
14 have 1k concurrent users per server at some point so I know it'll scale.
15 Did you have any problems, weird firewalls blocking your servers, latency
16 connection to the server, load balancers didn't like it, weird connections
17 that hung around forever, and so forth.
18
19 Thanks in advance,
20 kashani

Replies

Subject Author
Re: [gentoo-server] syn cookies in real life Rob ter Haar <rob@××××××××.nl>
Re: [gentoo-server] syn cookies in real life Miguel Sousa Filipe <miguel@×××××××××××.pt>