LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: (failed) ddos attack against my lvs cluster

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: (failed) ddos attack against my lvs cluster
From: Jacob Coby <jcoby@xxxxxxxxxxxxxxx>
Date: Thu, 04 Nov 2004 10:55:32 -0500
Francois JEANMOUGIN wrote:
Anyway, It is now 24 hours they are playing like that, and I would like to
stop it. Do you have an idea? Don't tell me that I have to use iptables to
reduce the syn rate, I can't :). I have a lot of mobile clients, and the wap
gateways can send me a lot of valid syns.

You can try turning on tcp_syncookies:

echo 1 > /proc/sys/net/ipv4/tcp_syncookies

http://www.mail-archive.com/focus-linux@xxxxxxxxxxxxxxxxx/msg00185.html

-Jacob
<Prev in Thread] Current Thread [Next in Thread>