LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

Re: Limiting number of users accessing Real Servers via LVS configured

To: "lvs-users@xxxxxxxxxxxxxxxxxxxxxx" <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: Re: Limiting number of users accessing Real Servers via LVS configured inNAT mode
From: "Matthew S. Crocker" <matthew@xxxxxxxxxxx>
Date: Mon, 24 Sep 2001 08:22:49 -0400 (EDT)
On Mon, 24 Sep 2001, Joseph Mack wrote:

> > I want to limit number of users accessing the LVS services at any given 
> > time. How can I do it.
>
> There's no easy way to do this. Most OS go to great pains to allow
> all the connections requested and to slice up the resources so that
> everyone gets an equal share. People have invented schemes
> to limit the number of connections to an LVS before but they haven't
> been incorporated into LVS. Havc a look at the archives.

One feature I would like to have in LVS is the ability to limit the number
of new connections/sec from a specific IP address.  Now that I have 4 Real
Servers in my LVS handling mail, the spammers just love opening a couple
thousand connections to send in the mail.   I end up block most at the
mail server but the connections still show up in LVS.

I know this would be dangerous and could open up DoS attacks by forging
inbound connections but if something could be done it would be great.

-Matt
-- ----------------------------------------------------------------------
Matthew S. Crocker
Vice President / Internet Division         Email: matthew@xxxxxxxxxxx
Crocker Communications                     Phone: (413) 587-3350
PO BOX 710                                 Fax:   (413) 587-3352
Greenfield, MA 01302-0710                  http://www.crocker.com
----------------------------------------------------------------------



<Prev in Thread] Current Thread [Next in Thread>