LinuxQuestions.org
Visit Jeremy's Blog.
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices

Reply
 
Search this Thread
Old 02-03-2012, 02:08 PM   #1
dlugasx
Member
 
Registered: Dec 2008
Location: Germany/Poland
Distribution: CentOS / Debian / Solaris / RedHat
Posts: 246

Rep: Reputation: 18
openvz - limit IP connections - debian 6 VPS


Hello everone,

I have realy big problem with my VPS. I cant limit connection per IP using iptables.

This is my linux kernel version:

Code:
Linux my.server.com 2.6.18-028stab092.1 #1 SMP Wed Jul 20 19:47:12 MSD 2011 x86_64 GNU/Linux
Here You can find all iptables modules:

Code:
cat /proc/net/ip_tables_matches
helper
conntrack
length
ttl
tcpmss
multiport
multiport
limit
tos
state
icmp
udp
tcp
and this is part of my firewall script responsible for SLOWLORIS defend

Code:
#!/bin/sh

# Clean all rules

iptables -F
iptables -F INPUT
iptables -F FORWARD
iptables -F OUTPUT
iptables -F -t mangle
iptables -F -t nat
iptables -X

# Setup new rules
iptables -P INPUT DROP
iptables -P OUTPUT ACCEPT
iptables -P FORWARD ACCEPT
iptables -N syn_flood


iptables -A INPUT -i lo -j ACCEPT
iptables -A OUTPUT -o lo -j ACCEPT

iptables -A INPUT -p tcp --dport 22 -j ACCEPT


iptables -A INPUT -p tcp --dport 80 -m state --state NEW -m recent --set --name Slowloris
iptables -A INPUT -p tcp --dport 443 -m state --state NEW -m recent --set --name Slowloris
iptables -A INPUT -p tcp --dport 80 -m state --state NEW -m recent --name Slowloris --update --seconds 60
iptables -A INPUT -p tcp --dport 443 -m state --state NEW -m recent --name Slowloris --update --seconds 60
I dont know why its not working. After execution I have received following error:

Code:
/etc/init.d/firewall
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name
iptables: No chain/target/match by that name

Does any body knows why ? How to limit ip connection in my super duper VPS ? Who can help me ?


regards

Dlugasx
 
Old 02-19-2012, 06:53 PM   #2
unSpawn
Moderator
 
Registered: May 2001
Posts: 27,277
Blog Entries: 54

Rep: Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852Reputation: 2852
Quote:
Originally Posted by dlugasx View Post
I cant limit connection per IP using iptables. (..) I dont know why its not working. (..) Does any body knows why ?
It's a shortcoming in VPS. Netfilter just doesn't work in a guest like you would expect it to work on a regular machine.


Quote:
Originally Posted by dlugasx View Post
How to limit ip connection in my super duper VPS ?
If your dom-0 owner isn't able or willing to make the required iptables modules available to you I guess you'll have to live with it.


//NTLB
 
  


Reply

Tags
attack, flood, loris, slow, syn


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
openvz node with only one vps rpereyra Linux - Virtualization and Cloud 3 06-06-2011 10:10 AM
CentOS VPS Setup Problems (connections) Cub3 Linux - Newbie 13 03-09-2011 08:56 AM
LXer: How To Upgrade Debian Lenny (Debian 5.0) To Squeeze (Debian 6.0) On Xen VPS LXer Syndicated Linux News 0 03-09-2011 05:20 AM
OpenVZ and Slackware running on vps astanton Slackware 1 03-08-2011 02:08 AM
limit connections Smokey Slackware 1 10-13-2004 02:22 AM


All times are GMT -5. The time now is 07:12 PM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration