From owner-freebsd-security@FreeBSD.ORG  Mon Jan 10 12:33:07 2005
Return-Path: <owner-freebsd-security@FreeBSD.ORG>
Delivered-To: freebsd-security@freebsd.org
Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125])
	by hub.freebsd.org (Postfix) with ESMTP id 3EA2C16A4CE
	for <freebsd-security@freebsd.org>;
	Mon, 10 Jan 2005 12:33:07 +0000 (GMT)
Received: from hotmail.com (bay21-f40.bay21.hotmail.com [65.54.233.129])
	by mx1.FreeBSD.org (Postfix) with ESMTP id F28F843D5A
	for <freebsd-security@freebsd.org>;
	Mon, 10 Jan 2005 12:33:06 +0000 (GMT)
	(envelope-from carlmarkbsd@hotmail.co.uk)
Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC;
	 Mon, 10 Jan 2005 04:33:06 -0800
Message-ID: <BAY21-F405B9FA87CFBE2CE0EC4B5EE970@phx.gbl>
Received: from 194.210.96.165 by by21fd.bay21.hotmail.msn.com with HTTP;
	Mon, 10 Jan 2005 12:32:37 GMT
X-Originating-IP: [194.210.96.165]
X-Originating-Email: [carlmarkbsd@hotmail.co.uk]
X-Sender: carlmarkbsd@hotmail.co.uk
From: "Carl Mark" <carlmarkbsd@hotmail.co.uk>
To: freebsd-security@freebsd.org
Date: Mon, 10 Jan 2005 12:32:37 +0000
Mime-Version: 1.0
Content-Type: text/plain; format=flowed
X-OriginalArrivalTime: 10 Jan 2005 12:33:06.0470 (UTC)
	FILETIME=[89166460:01C4F710]
Subject: connection limit with ipfw
X-BeenThere: freebsd-security@freebsd.org
X-Mailman-Version: 2.1.1
Precedence: list
List-Id: Security issues [members-only posting]
	<freebsd-security.freebsd.org>
List-Unsubscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-security>,
	<mailto:freebsd-security-request@freebsd.org?subject=unsubscribe>
List-Archive: <http://lists.freebsd.org/pipermail/freebsd-security>
List-Post: <mailto:freebsd-security@freebsd.org>
List-Help: <mailto:freebsd-security-request@freebsd.org?subject=help>
List-Subscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-security>,
	<mailto:freebsd-security-request@freebsd.org?subject=subscribe>
X-List-Received-Date: Mon, 10 Jan 2005 12:33:07 -0000

Hello folks,

  I'm trying to set up a ruleset that limits every user to X tcp 
connections, since I have 300 active users on each server. I've been trying 
to work it out with the ipfw limit but I really don't know how effective it 
is.

For example:

  ipfw -q add 15 allow tcp from me to any 80 limit dst-port X keep-state out 
setup


Will this limit the whole machine to X connections that match the rule? I 
wanted to build somehting that would limit every user to X conns without 
having one rule for each user using the "uid" directive.

Thanks for your precious help.
Regards,
Carl

_________________________________________________________________
It's fast, it's easy and it's free. Get MSN Messenger today! 
http://www.msn.co.uk/messenger