LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Protecting from SYN floods and other asshole people.

To: "Matthew S. Crocker" <matthew@xxxxxxxxxxx>
Subject: Re: Protecting from SYN floods and other asshole people.
Cc: "lvs-users@xxxxxxxxxxxxxxxxxxxxxx" <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
From: Julian Anastasov <ja@xxxxxx>
Date: Fri, 31 Aug 2001 22:53:42 +0000 (GMT)
        Hello,

On Fri, 31 Aug 2001, Matthew S. Crocker wrote:

> tcpserver is rejecting connections (I think).   Can I put an iptables
> entry on the director to block the offending CLass C?  Or, does LVS happen
> before the iptable stuff?

        LVS is designed to work after any kind of firewall rules. So,
you can put your ipchains/iptables rules safely. If you are using iptables
put them on LOCAL_IN, not on FORWARD. The LVS packets do not go through
FORWARD.

> -Matt


Regards

--
Julian Anastasov <ja@xxxxxx>



<Prev in Thread] Current Thread [Next in Thread>