Snort mailing list archives
RE: tcp flood
From: Matt Kettler <mkettler () evi-inc com>
Date: Tue, 08 Mar 2005 11:07:06 -0500
At 08:16 PM 3/7/2005, Joaquin Grech wrote:
Matt, I am checking your solutions. I am looking into a way to do the limit through IPTables but I can't find a way to do so per ip (or if the attack is massive, per general connection). Do you know the command or where to get that extension you mention?
Erk, you're right, iptables --limit is on a per-rule basis, not on a per source address...
------------------------------------------------------- SF email is sponsored by - The IT Product Guide Read honest & candid reviews on hundreds of IT Products from real users. Discover which products truly live up to the hype. Start reading now. http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click _______________________________________________ Snort-users mailing list Snort-users () lists sourceforge net Go to this URL to change user options or unsubscribe: https://lists.sourceforge.net/lists/listinfo/snort-users Snort-users list archive: http://www.geocrawler.com/redir-sf.php3?list=snort-users
Current thread:
- tcp flood Joaquin Grech (Mar 06)
- Re: tcp flood Matt Kettler (Mar 07)
- RE: tcp flood Joaquin Grech (Mar 07)
- Message not available
- RE: tcp flood Matt Kettler (Mar 08)
- Re: tcp flood Matt Kettler (Mar 07)
- <Possible follow-ups>
- Re: tcp flood SN ORT (Mar 07)
- Re: tcp flood Matt Kettler (Mar 07)
- RE: tcp flood Joaquin Grech (Mar 08)
- Re: tcp flood Matt Kettler (Mar 07)
- RE: tcp flood SN ORT (Mar 08)
- Re: tcp flood Matt Kettler (Mar 08)