Re: syncache testing

From: Barry Irwin (bvi@itouchlabs.com)
Date: 07/16/02


Date: Tue, 16 Jul 2002 05:15:13 +0200
From: Barry Irwin <bvi@itouchlabs.com>
To: zhang jack <jack_zhangcl@hotmail.com>


Yes, I make use of ipfw and the separate NAT daemon, however. Given it some
more thought and I'm not sure if this would work as expected ( would be very
nice if it does, looking forward to the outcomes of your testing).

The second method I suggested, will work as the packets are being processed
by the local host, however you haev an additioanl software component and
load on the gateway/firewall. The sould work for beefing up the security of
your web servers if you then firewalled them from connecting to anywhere but
there local subnet, as all the Internet faccing communications is via the
reverse proxy.

Barry

On Tue 2002-07-16 (02:58), zhang jack wrote:
>
> Thanks for your reply.
> I have used Ipfilter,did you mean using port redirecting?
> rdr fxp0 210.96.1.1 port 80 -> 192.168.1.1 port 80
> can it pass though syncache? I know Ipfilter hook the packets
> in the IP level.
>
>
>
> >From: Barry Irwin <bvi@itouchlabs.com>
> >To: zhang jack <jack_zhangcl@hotmail.com>
> >CC: security@FreeBSD.ORG
> >Subject: Re: syncache testing
> >Date: Tue, 16 Jul 2002 04:42:12 +0200
> >
> >Hi
> >
> >I'm not overly familiar with the syncache code, but you _may_ be able to
> >make use of the syncache mitigation by having your server sitting behind
> the
> >BSD box, with traffic being natted. A solution that may work better is to
> >have a reverse proxy of sorts running on the BSD system which proxies
> >requests to your webservers.
> >
> >Barry
> >
> >
> >On Tue 2002-07-16 (02:24), zhang jack wrote:
> > >
> > > Hi,
> > > I am testing syncache on FreeBSD 4.6 stable,and it works fine,
> > > but I found it *only* protect syn flooding of itself,can it act
> > > as a gateway( or firewall ) to protect my www server?
> > > can anyone help me?
> >
> >--
> >Barry Irwin bvi@itouchlabs.com +27214875177
> >Systems Administrator: Networks And Security
> >iTouch TAS http://www.itouchlabs.com South Africa
>
>
>
>
> _________________________________________________________________
> 享用世界上最大的电子邮件系统— MSN Hotmail。http://www.hotmail.com/cn
>
>
> To Unsubscribe: send mail to majordomo@FreeBSD.org
> with "unsubscribe freebsd-security" in the body of the message
>
>

--
Barry Irwin		bvi@itouchlabs.com			+27214875177
Systems Administrator: Networks And Security
iTouch TAS 		http://www.itouchlabs.com		South Africa
To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message


Relevant Pages

  • Re: Racoon SA Hard/Soft Lifetimes
    ... However I can find mo mention of any of the net.key.* sysctls in the man ... Systems Administrator: Networks And Security ...
    (FreeBSD-Security)
  • RE: [Full-Disclosure] RE: MS SQL WORM IS DESTROYING INTERNET BLOCK PORT 1434!
    ... Subject: RE: MS SQL WORM IS DESTROYING INTERNET ... Perhaps some of the .edu admins need to ... >basic network design concepts and security. ... But the admins whose networks got hit *still* didn't ...
    (Full-Disclosure)
  • Re: << SBS News this week 7/25/2004>>
    ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
    (microsoft.public.backoffice.smallbiz2000)
  • Re: << SBS News this week 7/25/2004>>
    ... > Homeland security has become a key issue in the US. ... > the Virginia Cyber-Crime Strike Force. ... > Fifteen employees at Los Alamos National Laboratory ... > networks is urgently required but agreed to work ...
    (microsoft.public.windows.server.sbs)
  • Re: [Full-disclosure] A Botted Fortune 500 a Day
    ... I believe security of an organisation is orthogonal to the number of ... >> Fortune 500 companies have more employees than some ISPs have customers. ... > compromises on their internal networks. ...
    (Bugtraq)