Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Rob
Date: Tuesday, October 23, 2007 - 5:59 pm

On 10/23/07, david l goodrich <dlg@dsrw.org> wrote:

Whoops, that was a big ol' typo. That should've been a pass, sorry.


Huh.

What's your output from pfctl -s rules -v ?

Also, I should parrot some of the earlier conversations that have been
on this list on this subject (limiting attempts at ssh attacks). Doing
this with a max-src-conn-rate rule probably isn't what you really want
to do anyway; there are some good log file analyzers which would be
better suited to this (see http://www.ossec.net/,
http://www.ossec.net/en/attacking-loganalysis.html, and
http://marc.info/?l=openbsd-misc&m=118660109014882&w=2); strong ssh
passwords are the best defense against dictionary attacks; etc. At
best, all you're really doing is keeping your authlog a bit leaner,
and maybe compiling a list of evildoers.

- R.

- R.
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 12:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 1:58 pm)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 2:46 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 2:55 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 5:30 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:59 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 7:36 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:02 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:23 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 1:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 5:26 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 8:40 am)