LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: (failed) ddos attack against my lvs cluster

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: (failed) ddos attack against my lvs cluster
From: Jacob Coby <jcoby@xxxxxxxxxxxxxxx>
Date: Thu, 04 Nov 2004 11:00:31 -0500
Jacob Coby wrote:
You can try turning on tcp_syncookies:

echo 1 > /proc/sys/net/ipv4/tcp_syncookies

http://www.mail-archive.com/focus-linux@xxxxxxxxxxxxxxxxx/msg00185.html

I forgot to mention that I've had tcp_syncookies enabled on individual systems for about 3 years now with no problems. I've had it enabled on every machine in a LVS-DR cluster for 6 months with no problems.

The email I quoted just said everything I wanted to say.

-Jacob
<Prev in Thread] Current Thread [Next in Thread>