|
From: Bruce S. <bw...@ar...> - 2003-05-29 17:26:38
|
> >>For all the logging you might want to add limit options to not get into
> >>troubles when flouded with invalid or block packages (denial of service!)
> >
> > Yes, I've seen those, ... somewhere.
> > Any idea where I "borrow" some samples?
>
> See the iptables tutorial I referenced at the end of my last mail.
The tutorial has lines like this at the END of each main chain
(INPUT, OUTPUT and FORWARD):
$IPTABLES -A FORWARD -m limit --limit 3/minute --limit-burst 3 -j LOG \
--log-level DEBUG --log-prefix "IPT FORWARD packet died: "
Those are the ONLY places it has any "--limit*" rules.
Correct if I'm wrong, but since it's jumping to LOG, it's not preventing
anything (LOG returns after logging the packet). So it's only logging
the over-limits, and not doing anything to stop DOS attacks.
I guess it's relying on the catch-all policy of DENY to stop anything
that's not accepted (including DOS attacks).
So it really does no good in my script, other than maybe saving a few
entries in the log. Is that really needed? Syslog normally combines
duplicate entries anyway.
I have seen specific "--limit" iptable statements specific for different
kind of DOS attacks, but I don't remember where I saw them off hand.
And now I'm not sure they are needed ... Anyone?
- BS
|