iptables & 2.4.8-26mdk Kernel
I've had a mandrake box up since about Jan. I run a small web server. I got tired of seeing all the scriptkiddies searching for windows CMD.EXE and ROOT.EXE etc., so I have been using iptables to DROP their IP into never-never land. I've also done the same for the scanb---tards that insist on filling my dmesg with nmap scan audit entries.
Problem is this, I've now got about 1800!! entries in iptables on the INPUT chain, and it appears that it is no longer dropping some of these IP's (Filling my logs again) It seems to be for the last few hosts I added.
Question is - Is there some parameter that I may have to change to allow for this many entries, and then re-compile? I'm assuming that I've 'filled' the space reserved for this in my kernel and it is ignoring some entries.
Maybe I should create some new chains (tables) and move my entries around, haven't tried that yet
I'm Stumped
Any Help?
UPDATE - Sure enough, If I put a rule at the end of the table it has no effect but near the top of the table it works fine...
Last edited by rgedye; 04-24-2002 at 07:39 PM.
|