Re: [fw-wiz] PIX Questions.

From: Dave Rinker (firewall@dsrtech.com)
Date: 03/18/03

  • Next message: David Lang: "Re: [fw-wiz] Stateful Proxying?"
    From: Dave Rinker <firewall@dsrtech.com>
    To: Firewall Wizards <Firewall-Wizards@honor.icsalabs.com>
    Date: 17 Mar 2003 19:06:56 -0500
    

    You can add to the end of your static command either the number of max
    connections or the max number of half open connections. (max_conns or
    emb_limit)

    This is from all IPs, I know no way to restrict by the same IP. Link
    provided below. You might want to look at the "timeout" command to deal
    with the same IP request.

    http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_reference_chapter09186a0080104255.html#1026694

    On Mon, 2003-03-17 at 13:49, George J. Jahchan, Eng. wrote:
    > I need to limit the maximum number of simultaneous inbound connections to a
    > server through a PIX 515 (6.22). I did not select it, but that is what I
    > have to work with. Is it possible to limit the number of inbound connections
    > it will allow as follows:
    >
    > Maximum number of simultaneous connections from all IP addresses to a
    > host/port combo in DMZ.
    >
    > Maximum number of simultaneous connections from the same IP address to a
    > host/port combo in DMZ.
    >
    > I know the Lucent Brick allows the first item and NetFilter/IPtables (with
    > some P-O-M patches) allows both limitations. How about the PIX?
    > TIA
    >
    > _______________________________________________
    > firewall-wizards mailing list
    > firewall-wizards@honor.icsalabs.com
    > http://honor.icsalabs.com/mailman/listinfo/firewall-wizards

    _______________________________________________
    firewall-wizards mailing list
    firewall-wizards@honor.icsalabs.com
    http://honor.icsalabs.com/mailman/listinfo/firewall-wizards


  • Next message: David Lang: "Re: [fw-wiz] Stateful Proxying?"

    Relevant Pages

    • RE: [fw-wiz] PIX Questions.
      ... I need to limit the maximum number of simultaneous inbound connections ... to a server through a PIX 515. ... host/port combo in DMZ. ... Maximum number of simultaneous connections from the same IP address to a ...
      (Firewall-Wizards)
    • Re: Pix & limit number of connections per host?
      ... simultaneous connections to a given host? ... to crash when it gets overwhelmed by a huge number of connections. ... be nice to have only 25 connections or so to this given host. ... On the end of a static command you ...
      (comp.dcom.sys.cisco)
    • Re: Pix & limit number of connections per host?
      ... simultaneous connections to a given host? ... to crash when it gets overwhelmed by a huge number of connections. ... be nice to have only 25 connections or so to this given host. ... On the end of a static command you will ...
      (comp.dcom.sys.cisco)
    • Re: Pix & limit number of connections per host?
      ... to crash when it gets overwhelmed by a huge number of connections. ... be nice to have only 25 connections or so to this given host. ... Christoph Gartmann ... On the end of a static command you will ...
      (comp.dcom.sys.cisco)
    • Re: Developing a server receiving multiple sockets
      ... > between any 2 connections, except that they are vying for the ... The "service time" computation involves less guesswork. ... On the other hand, if your clients were on a dialup, ... 15 times as many simultaneous connections to support. ...
      (comp.os.linux.development.apps)