Gentoo Archives: gentoo-user

From: James <wireless@×××××××××××.com>
To: gentoo-user@l.g.o
Subject: [gentoo-user] Re: HA firewall (conntrack-tools)
Date: Tue, 22 Jun 2010 18:05:03
Message-Id: loom.20100622T193708-258@post.gmane.org
In Reply to: Re: [gentoo-user] HA firewall (conntrack-tools) by Mick
1 Mick <michaelkintzios <at> gmail.com> writes:
2
3 Howdy Mick!
4
5 > I can't add anything about conntrackd, because I have not used it, but
6 > I'd recommend to use the limit module and set it to something sensible
7 > (e.g. 3/minute) when logging invalid packets, if you want to avoid
8 > bogging down your fw. So use something like:
9
10 Well, between needing a firewall that does not fail (HA via redundancy),
11 and a need to get 'up 2 speed' on the latest with iptables, I'm taking the
12 plunge here...
13
14 conntrackd provide what looks like a cool roll over mechanism similar
15 to OpenBSD's carp and pfsync.
16
17 http://www.openbsd.org/faq/pf/carp.html
18
19 You may get a few private email, if I do not find a forum for ideas and
20 experimentation......
21
22 > -m limit --limit 1/minute
23
24 > You could also add --limit-burst in the same fashion again to limit
25 > DoS attacks, at least on the Internet facing NICs/ports.
26
27 Nice to know.
28
29
30 Thanks Mick,
31
32 James