Menu ▾ ▴

#1 Pre-connection server bans

open
nobody
None
5
2009-11-08
2009-11-08
Anonymous
No

This feature allows server administrators to reduce traffic caused by server attacks. Before a client or server connection is registered, the server checks the connection's address on a blacklist database. That database holds CIDR-style address lists, including expiration time for each entry.
Once the connection is found to be black-listed, the connection is dropped immediately and a firewall rule (DROP) is set to lock out the particular connection.

A central blacklist database service can be used by everyone to maintain blacklisted addresses (in some way like spamhaus).

Discussion


Log in to post a comment.