[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Tarpitting?



On Mon, Nov 03, 2003 at 05:19:32PM -0500, Erik Bourget wrote:
> I know that there are patches to tcpserver to limit per IP; are there per
> subnet?  I'd rather do the matching at tcpserver than at iptables because it's
> meant to be centrally modified from another machine and propagated out to the
> frontend MXs; remotely/automatically modifying firewall rules makes me upset.

Take a look at the ipsvd package if you're interested.  It implements a
tcpserver alike service daemon with extended instructions for connection
handling, including per-host/ip/subnet concurrency.

Regards, Gerrit.
-- 
Open projects at http://smarden.org/pape/.