Re: [PATCH RFC] netfilter: iptables target SYNPROXY

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Changli Gao
Date: Tuesday, May 25, 2010 - 7:42 am

On Tue, May 25, 2010 at 8:17 PM, Jozsef Kadlecsik
<kadlec@blackhole.kfki.hu> wrote:

Yea. Only MSS option is  supported. But it is better than being DoSed.
And you can set a threshold for SYNPROXY with limit match, then there
isn't any difference if there isn't any SYN-flood attack.


Yes, both can be true. You descried above is called SYNDefender by
Checkpoint, and it doesn't work as well as SYNPROXY.

http://www.usenix.org/events/sec01/invitedtalks/oliver.pdf

-- 
Regards,
Changli Gao(xiaosuo@gmail.com)
--
To unsubscribe from this list: send the line "unsubscribe netdev" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
[PATCH RFC] netfilter: iptables target SYNPROXY, Changli Gao, (Tue May 25, 12:06 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Jan Engelhardt, (Tue May 25, 3:36 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Changli Gao, (Tue May 25, 4:26 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Jan Engelhardt, (Tue May 25, 4:50 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Jozsef Kadlecsik, (Tue May 25, 5:17 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Changli Gao, (Tue May 25, 7:42 am)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Jozsef Kadlecsik, (Tue May 25, 12:03 pm)
Re: [PATCH RFC] netfilter: iptables target SYNPROXY, Changli Gao, (Tue May 25, 3:52 pm)