Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: <misc@...>
Cc: david l goodrich <dlg@...>
Date: Tuesday, October 23, 2007 - 10:36 pm

On October 23, 2007 07:30:25 pm david l goodrich wrote:

I tried various combinations on my test machine and noticed the following
pattern. Setting the max-src-conn to be twice the max-src-conn-rate seems to
work better at stopping brute-force SSH attempts. Probably there is no
rational basis for this observation and there must be some other explanation.
I did try a few combinations and it seemed to have had a positive impact in
getting the IP address to the sshd_attackers table at the right
max-src-conn-rate.

So I am wondering if

pass in log proto tcp from any to any port ssh keep state (max-src-conn 6
max-src-conn-rate 3/30, overload flush global)

would be an appropriate thing for you to try.

Anyways, hope this helps in some way.

--
Vijay Sankar, M.Eng., P.Eng.
President & CEO
ForeTell Technologies Limited
59 Flamingo Avenue, Winnipeg, MB Canada R3J 0X6
Phone: +1 204 885 9535, E-Mail: vsankar@foretell.ca

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 3:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 4:58 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:55 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 4:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 8:26 am)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 8:30 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 10:36 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 8:59 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:02 am)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 5:46 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:23 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 11:40 am)