Results 1 to 6 of 6
Hybrid View
-
01-13-2005, 05:49 AM #1Web Hosting Master
- Join Date
- Feb 2002
- Posts
- 2,120
How-to: Drop INVALID SYN packets with iptables
Feel free to use the following iptable commands below to drop INVALID SYN packets that sometimes are also used to flood the server..
/sbin/iptables -A INPUT -i eth0 -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j DROP
/sbin/iptables -A INPUT -i eth0 -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
/sbin/iptables -A INPUT -i eth0 -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
--
Jeff @ LinuxAdminLast edited by apollo; 01-13-2005 at 05:52 AM.
-
03-13-2005, 07:03 PM #2Web Hosting Guru
- Join Date
- Oct 2004
- Posts
- 302
Do you think they are good for RHE3 and Fedora 1,2?
-
03-14-2005, 03:24 AM #3Web Hosting Master
- Join Date
- Feb 2002
- Posts
- 2,120
Sure! I see no problem. Make sure you enter/execute above commands in correct order in case you have apf or any other custom rule sets..
-
03-14-2005, 08:35 AM #4Web Hosting Guru
- Join Date
- Oct 2004
- Posts
- 302
I have installed apf and bfd - that won't be a problem?
-
03-19-2005, 08:51 PM #5
If you're using APF, you'd want to put something like this
$IPT -A INPUT -i $IN_IF -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j DROP
$IPT -A INPUT -i $IN_IF -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
$IPT -A INPUT -i $IN_IF -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
$IPT -A OUTPUT -o $OUT_IF -p tcp --tcp-flags ALL ACK,RST,SYN,FIN -j DROP
$IPT -A OUTPUT -o $OUT_IF -p tcp --tcp-flags SYN,FIN SYN,FIN -j DROP
$IPT -A OUTPUT -o $OUT_IF -p tcp --tcp-flags SYN,RST SYN,RST -j DROP
However, I'd be incredibly surprised if something like this wasn't already in place in apfTom Whiting, WHMCS Guru extraordinaire
Linux problems? WHMCS Problems? Give me a shout
Check out my WHMCS Addons
-
07-30-2005, 05:10 PM #6Web Hosting Guru
- Join Date
- Apr 2002
- Location
- Troy, MI
- Posts
- 324
just trolling old threads -- /etc/apf/bt.rules
Ryan MacDonald
Lead Administrator | TotalChoice Hosting
Choice Does Matter! | Serving over 26,000 clients