Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
To: Calomel <bsdlists@...>
Cc: <misc@...>
Date: Wednesday, October 24, 2007 - 12:23 am

On Tue, Oct 23, 2007 at 05:46:45PM -0400, Calomel wrote:

I didn't respond to this until now, because I wanted to do some
research first. As the hosts that are being blocked by this
aren't hosts I control, I needed to set up some access on the
outside.

So it looks like i can run 'nmap -sS -p22 25.103.82.80/28' until
doomsday and it will always show as a passed connection.

But when i start telnetting to port 22 on machines in this
subnet, the fourth 'telnet' connection is blocked, no matter
which host I hit previously. So I think that you are correct
in that the attackers are not initially completing the 3-way
handshake, and are thus not tripping the filter.

I'll look in to max-src-states, but I think now that I've shown
that the actual "attack" (if that's what they are) attempts are
blocked properly, I'm not terribly concerned if they can scan the
subnet.

Thanks,
--david

>

which
had a name of signature.asc]

[demime 1.01d removed an attachment of type application/pgp-signature which had a name of signature.asc]

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 3:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 4:58 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:55 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 4:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 8:26 am)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 8:30 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 10:36 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 8:59 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:02 am)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 5:46 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Wed Oct 24, 12:23 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 11:40 am)