Re: Urgent: Under attack - need tcpdrop help



On Tue, May 24, 2011 at 4:29 PM, Andy Wodfer <wodfer@xxxxxxxxx> wrote:
Hi,
One of my FreeBSD servers is currently being attacked (DDOS) and I'm
blocking IP addresses in my firewall. However, there are a large number of
hung tcp connections and I want them gone.


I know it's not what you're asking but for the future try fail2ban. I
can gladly post a simple how to here for FreeBSD.

It's a very simple solution but I have been keeping off pests quite
well with fail2ban. I think it's an awesome and simple framework to
automatically ban IPs and they just move on to the th next server. In
fact you can see the bannings diminish in time as they are the one
that get tired ;-)

Good luck,

--
Alejandro Imass
_______________________________________________
freebsd-questions@xxxxxxxxxxx mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscribe@xxxxxxxxxxx"



Relevant Pages

  • Re: Urgent: Under attack - need tcpdrop help
    ... One of my FreeBSD servers is currently being attacked and I'm ... blocking IP addresses in my firewall. ... I know it's not what you're asking but for the future try fail2ban. ...
    (freebsd-questions)
  • Re: Dropping syn+fin replies, but not really?
    ... FreeBSD servers. ... on some of the hosts, and they constantly come back with a ... isn't relevant for the packets that are traversing the firewall: ... itself or just blocks SYN + FIN by itself, ...
    (FreeBSD-Security)
  • Re: Dropping syn+fin replies, but not really?
    ... FreeBSD servers. ... on some of the hosts, and they constantly come back with a ... isn't relevant for the packets that are traversing the firewall: ... itself or just blocks SYN + FIN by itself, ...
    (FreeBSD-Security)
  • ipnat proxy ftp module not working ?
    ... I have two freebsd servers: one with freebsd6.2 and new freebsd7.0. ... I use ipnat for nat and ipfw as firewall. ... When i try to connect to remote FTP server from my client and ... i receive data (file listing), files are diplayed but the connection is instatly broken. ...
    (comp.unix.bsd.freebsd.misc)