[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: Tarpitting?
On Mon, Nov 03, 2003 at 05:19:32PM -0500, Erik Bourget wrote:
> I know that there are patches to tcpserver to limit per IP; are there per
> subnet? I'd rather do the matching at tcpserver than at iptables because it's
> meant to be centrally modified from another machine and propagated out to the
> frontend MXs; remotely/automatically modifying firewall rules makes me upset.
Take a look at the ipsvd package if you're interested. It implements a
tcpserver alike service daemon with extended instructions for connection
handling, including per-host/ip/subnet concurrency.
Regards, Gerrit.
--
Open projects at http://smarden.org/pape/.