My iptables is setup to drop SYN flood records.
Code:
*filter
:INPUT ACCEPT [2:169]
:FORWARD ACCEPT [0:0]
:OUTPUT ACCEPT [35:4128]
:syn_flood - [0:0]
...
-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
-A syn_flood -m limit --limit 1/sec --limit-burst 3 -j RETURN
-A syn_flood -j DROP
My question is shouldn't the '-A syn_flood' lines come before the '-A INPUT'? Like:
Code:
-A syn_flood -m limit --limit 1/sec --limit-burst 3 -j RETURN
-A syn_flood -j DROP
-A INPUT -i lo -j ACCEPT
-A OUTPUT -o lo -j ACCEPT
Thanks