Security Basics mailing list archives

Re: what might be safe limit for iptable ?


From: Aarón Mizrachi <unmanarc () gmail com>
Date: Mon, 31 Aug 2009 12:45:40 -0430

On Domingo 30 Agosto 2009 09:47:21 J. Bakshi escribió:
Hello list,

I have a question in my mind during the configuration process of my
firewall. "limit" option is used to accept the ( safe, defined by us )
limit and we can drop everything else beyond that. And here I wounder to
know the "safe" limit for different services.

What might be the acceptable safe limit for ?

1> A very busy webserver ( port 80)
2> email
3> squid


It depends directly on the processor/network/speed capacity of your 
webserver/mailserver/proxyserver and your personal requirements, but in 
general, my suggestion is to avoid the "limit rate" option for public server, 
this is because it will drop valid and nonvalid connections as well on denial 
of service attacks.

Limit rate will be useful for many other pourporses, like cascade load 
balancing, and others. However, i think that "connlimit" is what you are 
looking for.


Please suggest
Thanks

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL
certificate.  We look at how SSL works, how it benefits your company and
how your customers can tell if a site is secure. You will find out how to
test, purchase, install and use a thawte Digital Certificate on your Apache
web server. Throughout, best practices for set-up are highlighted to help
you ensure efficient ongoing management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f72
7d1 ------------------------------------------------------------------------

-- 
Ing. Aaron G. Mizrachi P.    

http://www.unmanarc.com
Mobil 1: + 58 416-6143543
Mobil 2: + 58 424-2412503
BBPIN: 0x 247066C1

Attachment: signature.asc
Description: This is a digitally signed message part.


Current thread: