Gentoo Archives: gentoo-server

From: Rob ter Haar <rob@××××××××.nl>
To: gentoo-server@l.g.o
Subject: Re: [gentoo-server] syn cookies in real life
Date: Mon, 16 Aug 2004 16:02:40
Message-Id: 4120DAFB.6030208@nedlinux.nl
In Reply to: [gentoo-server] syn cookies in real life by Kashani
1 Kashani wrote:
2
3 > I've been Googling for a few hours looking for information from
4 >anyone actually using syn cookies in a production system. We'd been hit
5 >with a few syn floods recently and were looking at a number of ways to
6 >stop them.
7 >
8 > From my research it appears that syn cookies should not affect the
9 >TCP session. There are some references to syn cookies causing slow downs
10 >with SMTP and ftp, but nothing really concrete. Also most of the info is
11 >from 2001 when 2.4 came out and syn cookies were linked with the newer
12 >iptables code. Was looking for case studies and hard stats.
13 >
14 > I'd like to hear from anyone running web server farms that has syn
15 >cookies turned on. Ideally you'd be pushing a fair amount of traffic or
16 >have 1k concurrent users per server at some point so I know it'll scale.
17 >Did you have any problems, weird firewalls blocking your servers, latency
18 >connection to the server, load balancers didn't like it, weird connections
19 >that hung around forever, and so forth.
20 >
21 >Thanks in advance,
22 >kashani
23 >
24 >
25 hi,
26
27 We have syn cookies turned on since we had a attack (6 mbit) and without
28 syn cookies off the load of the servers where very high login in was
29 almost not possible.
30 and when syn cookies turned on the load go down and the servers working
31 ok slow but website where up again.
32 and we have have no problems everything is normal.
33
34 grzt rob ter haar
35 NedLinux.nl