Re: Dynamic firewall based on bandwidth usage ?



One idea could be using accouting on iptables and limit traffic by this way....
You shoul look inside patchomatic to see if there is any way to limit traffic by ip ( i think that a module exist for that but
check it yoursel to be sure... ) ( netfilter.samba.org )

Alain


Hello,
I have a common problem but cannot find a solution.

My setup :
all servers are Redhat Enterprise 4
CISCO PIX in front on a HTTP load Balancer/failover (called a director
in the L.V.S. jargon) that sends requests to 4 web servers (cluster
setup based on Linux Virtual Server include in redhat cluster suite).

Now my prob :-)

From time to time users download our site and block all http connexion,
and worst, use all our bandwidth. So I have to block (or redirect) those
network abusers after a download limit (for ex : 1Gb per day) for lets
say 1day.

Because of the director, I cannot use the apache2 mod_cband.

My first though is to look at the iptables on the director but I cannot
find any information about that kind of setup.

Do you know if it is possible using build in linux tools(iptables ?).

If not, do you know some hardware appliance that could do that ?

Thanks !




Relevant Pages

  • Re: Dynamic firewall based on bandwidth usage ?
    ... I saw it but redhat 4 is using an older version ... director in the L.V.S. jargon) that sends requests to 4 web servers ... (cluster setup based on Linux Virtual Server include in redhat ... My first though is to look at the iptables on the director but I ...
    (Security-Basics)
  • Re: Small Redundant web/mail setup
    ... Subject: Small Redundant web/mail setup ... would serve these files via nfs to the application servers. ... get good hardware. ...
    (freebsd-questions)
  • RE: A question about a basic security setup...
    ... A question about a basic security setup... ... > I was thinking of running iptables on the dual homed host, ... What you are looking for here, is an "application proxy" type firewall. ...
    (Security-Basics)
  • Re: oops with dual xeon 2.8ghz  4gb ram +smp,qsoftware=A0raid?=,qlvm?=,qand=A0xfs?=
    ... fairly similar setup as yours: ... Running XFS, exporting via NFS ... I have seen quite a lot of Oops's on these servers, ... Regarding ext3... ...
    (Linux-Kernel)
  • Re: Simple setup of domain servers for school labs
    ... routines that perform network setup, user setup, server configuration and ... 2003 SP2 servers setup by a number of contractors. ... all limping along in school labs. ... site support or central support. ...
    (microsoft.public.windows.server.sbs)

Quantcast