LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 11-23-2004, 02:14 PM   #1
topcat
Member
 
Registered: Feb 2003
Distribution: ubuntu 6.06, ubuntu 7.04 AMD 64bit, 7.10 AMD 64bit
Posts: 62

Rep: Reputation: 15
IP blocking in IP Tables


My server gets hit like continuously and LDAP just cannot handle it. uses 95% of CPU, EVEN though its not an active server. Its the backup one. so obviously someone is targeting the IP.

How do i set up an IP rule or Rules to achieve the following:

a) if a particular IP sends more than X requests a minute that are to unknown users in the lookup table, then block them out.

b) Get a LOT of smtp requests. If get more than X requests a minute then block them out too.

Any ideas how to go about this? And how do i first ensure that I will not firewall myself out. I have been warned to take care of this, but with no luck.

thanks!!
 
Old 11-24-2004, 08:48 AM   #2
qwijibow
LQ Guru
 
Registered: Apr 2003
Location: nottingham england
Distribution: Gentoo
Posts: 2,672

Rep: Reputation: 47
just use the limit match.

first set a rule to allow all your trused IP's
then a limit match for the rest of the world on the ports you mentioned.
then a drop to kill all conections to the ports that didnt get through the limit match.

just make sure there is a rule to allow you to login (ssh ?) to the machine from the ip address / range that you login from.

i cant write the firewall for you, i dont know enough about the network environment, but you can get all the help you need from the nam page "man iptables"
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
IP Tables Jeewhizz Linux - Security 3 02-26-2009 01:27 PM
IP Tables help muru Linux - Security 3 09-27-2005 11:39 PM
IP TABLES help chrisfirestar Linux - Networking 2 10-29-2003 12:24 PM
IP Tables - What are they? yorkshiresteve Linux - Security 3 07-08-2003 04:34 AM
Ip Tables Mag|c Linux - Security 3 06-26-2003 10:06 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 04:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration