1 |
Mick <michaelkintzios <at> gmail.com> writes: |
2 |
|
3 |
Howdy Mick! |
4 |
|
5 |
> I can't add anything about conntrackd, because I have not used it, but |
6 |
> I'd recommend to use the limit module and set it to something sensible |
7 |
> (e.g. 3/minute) when logging invalid packets, if you want to avoid |
8 |
> bogging down your fw. So use something like: |
9 |
|
10 |
Well, between needing a firewall that does not fail (HA via redundancy), |
11 |
and a need to get 'up 2 speed' on the latest with iptables, I'm taking the |
12 |
plunge here... |
13 |
|
14 |
conntrackd provide what looks like a cool roll over mechanism similar |
15 |
to OpenBSD's carp and pfsync. |
16 |
|
17 |
http://www.openbsd.org/faq/pf/carp.html |
18 |
|
19 |
You may get a few private email, if I do not find a forum for ideas and |
20 |
experimentation...... |
21 |
|
22 |
> -m limit --limit 1/minute |
23 |
|
24 |
> You could also add --limit-burst in the same fashion again to limit |
25 |
> DoS attacks, at least on the Internet facing NICs/ports. |
26 |
|
27 |
Nice to know. |
28 |
|
29 |
|
30 |
Thanks Mick, |
31 |
|
32 |
James |