Re: Dynamic firewall based on bandwidth usage ?



On Sun, 08 Oct 2006 14:44:22 -0400
FM <dist-list@xxxxxxxxxxxxxxxxxx> wrote:

Hello,
I have a common problem but cannot find a solution.

My setup :
all servers are Redhat Enterprise 4
CISCO PIX in front on a HTTP load Balancer/failover (called a
director in the L.V.S. jargon) that sends requests to 4 web servers
(cluster setup based on Linux Virtual Server include in redhat
cluster suite).

Now my prob :-)

From time to time users download our site and block all http
connexion, and worst, use all our bandwidth. So I have to block (or
redirect) those network abusers after a download limit (for ex :
1Gb per day) for lets say 1day.

Because of the director, I cannot use the apache2 mod_cband.

My first though is to look at the iptables on the director but I
cannot find any information about that kind of setup.

Do you know if it is possible using build in linux
tools(iptables ?).

If not, do you know some hardware appliance that could do that ?

Cisco does that. Depending on which PIX and which version of the PIX,
you can do traffic shaping/policing based on a sliding window. Even a
Cisco 1750 serie will do it.

Then you can lower the quality of service to a level, that everybody
else get priority over them.

Hope this help


--
Thanks
http://www.911networks.com
When the network has to work



Relevant Pages

  • Remote Management of Bridged Cisco 837
    ... Cisco 837 and Pix 506e firewall. ... Currently I'm planning to setup the ...
    (comp.dcom.sys.cisco)
  • [fw-wiz] RE: PIX FW Failover & Hello Packet
    ... "Both PIX Fw is setup with..." ... >is it multicast or Cisco proprietary like Cisco CDP or something else? ... >the switch that does not have trunking, ...
    (Firewall-Wizards)
  • Re: Cisco Pix?
    ... setup a test lab if possible, download PIX docs from ... Cisco and setup the PIX and see if it works for you. ...
    (comp.security.firewalls)
  • Pix 520 - Can it log bandwidth usage?
    ... It's a very simple setup as I have little knowledge of Cisco Pix systems. ... All the servers behind the firewall are working fine with various web servers etc running and all accessible from the outside world. ...
    (comp.security.firewalls)
  • Re: Small Redundant web/mail setup
    ... Subject: Small Redundant web/mail setup ... would serve these files via nfs to the application servers. ... get good hardware. ...
    (freebsd-questions)