On October 23, 2007 07:30:25 pm david l goodrich wrote:
I tried various combinations on my test machine and noticed the following
pattern. Setting the max-src-conn to be twice the max-src-conn-rate seems to
work better at stopping brute-force SSH attempts. Probably there is no
rational basis for this observation and there must be some other explanation.
I did try a few combinations and it seemed to have had a positive impact in
getting the IP address to the sshd_attackers table at the right
max-src-conn-rate.
So I am wondering if
pass in log proto tcp from any to any port ssh keep state (max-src-conn 6
max-src-conn-rate 3/30, overload flush global)
would be an appropriate thing for you to try.
Anyways, hope this helps in some way.
--
Vijay Sankar, M.Eng., P.Eng.
President & CEO
ForeTell Technologies Limited
59 Flamingo Avenue, Winnipeg, MB Canada R3J 0X6
Phone: +1 204 885 9535, E-Mail: vsankar@foretell.ca
| Greg KH | [GIT PATCH] driver core patches against 2.6.24 |
| david | Re: Dual-Licensing Linux Kernel with GPL V2 and GPL V3 |
| Rob Landley | What still uses the block layer? |
git: | |
| Antonio Almeida | HTB accuracy for high speed |
| Alexey Dobriyan | Re: [GIT]: Networking |
| Jarek Poplawski | [PATCH] pkt_sched: Destroy gen estimators under rtnl_lock(). |
| Gerrit Renker | [PATCH 27/37] dccp: Integration of dynamic feature activation - part 2 (server side) |
