LVS
lvs-users
Google
 
Web LinuxVirtualServer.org

ip_vs_random_dropentry

To: "LinuxVirtualServer.org users mailing list." <lvs-users@xxxxxxxxxxxxxxxxxxxxxx>
Subject: ip_vs_random_dropentry
From: Jacob Coby <jcoby@xxxxxxxxxxxxxxx>
Date: Wed, 28 Sep 2005 12:24:20 -0400
I've been looking at the source code for ipvs 1.0.10 and noticed that ip_vs_random_dropentry does not send a RESET packet to the realserver. It is my understanding that this feature is to prevent SYN flood (and related) attacks, but it doesn't seem like it would be effective as the realserver will continue to SYN/ACK until it reaches tcp_synack_retries. You've potentially saved the director from attack, but lost the realserver(s).

Am I missing something, or is this by design?

--
-Jacob

<Prev in Thread] Current Thread [Next in Thread>