Re: FreeBSD firewall block syn flood attack

From: James Ainslie (james_at_starjuice.net)
Date: 05/20/03

  • Next message: Nikolay Kanchev: "Re: NAT+IPFW"
    Date: Tue, 20 May 2003 09:37:50 +0200
    To: Ryan James <ryan@mac2.net>
    
    

    On (2003/05/20 01:52), Ryan James wrote:n
    > Hello,
    >
    > I current have a FreeBSD 4.8 bridge firewall that sits between 7 servers and
    > the internet. The servers are being attacked with syn floods and go down
    > multiple times a day.
    >
    > The 7 servers belong to a client, who runs redhat.
    >
    > I am trying to find a way to do some kind of syn flood protection inside the
    > firewall.

    You could use snort quite effectively here. You can set up snort to act
    as an active packet filter, in conjunction with a firewall.

    Then obtain a few signature packets and craft a snort rule to activate
    the dropping of these packets. The problem with using an IDS in line
    with a firewall is that you run the horrible risk of false positives.

    Proceed with extreme caution. :)

    Hope that helps.

    James.

    -- 
    James Ainslie 
    Systems Administrator
    "Power corrupts, and absolute power corrupts absolutely"
    						Lord Acton
    	So who says FreeBSD isnt a corrupt OS?
    _______________________________________________
    freebsd-security@freebsd.org mailing list
    http://lists.freebsd.org/mailman/listinfo/freebsd-security
    To unsubscribe, send any mail to "freebsd-security-unsubscribe@freebsd.org"
    

  • Next message: Nikolay Kanchev: "Re: NAT+IPFW"

    Relevant Pages

    • RE: [opensuse] Two nics, two server, two networks
      ... On Friday 22 August 2008 21:58:10 James D. Parra wrote: ... I have two servers each with two nic's. ... internal network, however I have set up the other nic's on a different ... The subnet doesn't appear in the routing table, ...
      (SuSE)
    • Re: My Secondary Mail Server is downloading and resending Bogus Emails?
      ... it’s connected via NIS (it also serves as a secondary NIS server)… it ... provides authentication for other servers in the network. ... In fact it successfully serves as the smtp ... L. D. James ...
      (comp.mail.sendmail)
    • RE: [opensuse] php5 modules and Apache on Suse 10 {solved}
      ... James D. Parra escribió: ... I have two servers, each with Suse 10 installed, running apache with PHP5. ... when you view the phpinfo generated web page shows all of the ...
      (SuSE)
    • Re: Correction DNS woes
      ... James wrote: ... > servers, instead of internal web servers. ... > I not sure how to correct for using external DNS servers, ...
      (comp.unix.bsd.openbsd.misc)
    • Re: Correction DNS woes
      ... James wrote: ... > servers, instead of internal web servers. ... > I not sure how to correct for using external DNS servers, ...
      (comp.unix.bsd.openbsd.misc)