Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: Vijay Sankar
Date: Tuesday, October 23, 2007 - 7:36 pm

On October 23, 2007 07:30:25 pm david l goodrich wrote:

I tried various combinations on my test machine and noticed the following 
pattern. Setting the max-src-conn to be twice the max-src-conn-rate seems to 
work better at stopping brute-force SSH attempts. Probably there is no 
rational basis for this observation and there must be some other explanation. 
I did try a few combinations and it seemed to have had a positive impact in 
getting the IP address to the sshd_attackers table at the right 
max-src-conn-rate.

So I am wondering if

pass in log proto tcp from any to any port ssh keep state (max-src-conn 6  
max-src-conn-rate 3/30, overload <sshd_attackers> flush global)

would be an appropriate thing for you to try.

Anyways, hope this helps in some way.

-- 
Vijay Sankar, M.Eng., P.Eng.
President & CEO
ForeTell Technologies Limited
59 Flamingo Avenue, Winnipeg, MB Canada R3J 0X6
Phone: +1 204 885 9535, E-Mail: vsankar@foretell.ca
Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 12:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 1:58 pm)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 2:46 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 2:55 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 5:30 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:59 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 7:36 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:02 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:23 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 1:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 5:26 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 8:40 am)