From owner-freebsd-security@FreeBSD.ORG Mon Jan 10 12:33:07 2005 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3EA2C16A4CE for ; Mon, 10 Jan 2005 12:33:07 +0000 (GMT) Received: from hotmail.com (bay21-f40.bay21.hotmail.com [65.54.233.129]) by mx1.FreeBSD.org (Postfix) with ESMTP id F28F843D5A for ; Mon, 10 Jan 2005 12:33:06 +0000 (GMT) (envelope-from carlmarkbsd@hotmail.co.uk) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Mon, 10 Jan 2005 04:33:06 -0800 Message-ID: Received: from 194.210.96.165 by by21fd.bay21.hotmail.msn.com with HTTP; Mon, 10 Jan 2005 12:32:37 GMT X-Originating-IP: [194.210.96.165] X-Originating-Email: [carlmarkbsd@hotmail.co.uk] X-Sender: carlmarkbsd@hotmail.co.uk From: "Carl Mark" To: freebsd-security@freebsd.org Date: Mon, 10 Jan 2005 12:32:37 +0000 Mime-Version: 1.0 Content-Type: text/plain; format=flowed X-OriginalArrivalTime: 10 Jan 2005 12:33:06.0470 (UTC) FILETIME=[89166460:01C4F710] Subject: connection limit with ipfw X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 10 Jan 2005 12:33:07 -0000 Hello folks, I'm trying to set up a ruleset that limits every user to X tcp connections, since I have 300 active users on each server. I've been trying to work it out with the ipfw limit but I really don't know how effective it is. For example: ipfw -q add 15 allow tcp from me to any 80 limit dst-port X keep-state out setup Will this limit the whole machine to X connections that match the rule? I wanted to build somehting that would limit every user to X conns without having one rule for each user using the "uid" directive. Thanks for your precious help. Regards, Carl _________________________________________________________________ It's fast, it's easy and it's free. Get MSN Messenger today! http://www.msn.co.uk/messenger