From owner-freebsd-security@FreeBSD.ORG Mon Jan 10 12:33:07 2005 Return-Path: <owner-freebsd-security@FreeBSD.ORG> Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 3EA2C16A4CE for <freebsd-security@freebsd.org>; Mon, 10 Jan 2005 12:33:07 +0000 (GMT) Received: from hotmail.com (bay21-f40.bay21.hotmail.com [65.54.233.129]) by mx1.FreeBSD.org (Postfix) with ESMTP id F28F843D5A for <freebsd-security@freebsd.org>; Mon, 10 Jan 2005 12:33:06 +0000 (GMT) (envelope-from carlmarkbsd@hotmail.co.uk) Received: from mail pickup service by hotmail.com with Microsoft SMTPSVC; Mon, 10 Jan 2005 04:33:06 -0800 Message-ID: <BAY21-F405B9FA87CFBE2CE0EC4B5EE970@phx.gbl> Received: from 194.210.96.165 by by21fd.bay21.hotmail.msn.com with HTTP; Mon, 10 Jan 2005 12:32:37 GMT X-Originating-IP: [194.210.96.165] X-Originating-Email: [carlmarkbsd@hotmail.co.uk] X-Sender: carlmarkbsd@hotmail.co.uk From: "Carl Mark" <carlmarkbsd@hotmail.co.uk> To: freebsd-security@freebsd.org Date: Mon, 10 Jan 2005 12:32:37 +0000 Mime-Version: 1.0 Content-Type: text/plain; format=flowed X-OriginalArrivalTime: 10 Jan 2005 12:33:06.0470 (UTC) FILETIME=[89166460:01C4F710] Subject: connection limit with ipfw X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.1 Precedence: list List-Id: Security issues [members-only posting] <freebsd-security.freebsd.org> List-Unsubscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-security>, <mailto:freebsd-security-request@freebsd.org?subject=unsubscribe> List-Archive: <http://lists.freebsd.org/pipermail/freebsd-security> List-Post: <mailto:freebsd-security@freebsd.org> List-Help: <mailto:freebsd-security-request@freebsd.org?subject=help> List-Subscribe: <http://lists.freebsd.org/mailman/listinfo/freebsd-security>, <mailto:freebsd-security-request@freebsd.org?subject=subscribe> X-List-Received-Date: Mon, 10 Jan 2005 12:33:07 -0000 Hello folks, I'm trying to set up a ruleset that limits every user to X tcp connections, since I have 300 active users on each server. I've been trying to work it out with the ipfw limit but I really don't know how effective it is. For example: ipfw -q add 15 allow tcp from me to any 80 limit dst-port X keep-state out setup Will this limit the whole machine to X connections that match the rule? I wanted to build somehting that would limit every user to X conns without having one rule for each user using the "uid" directive. Thanks for your precious help. Regards, Carl _________________________________________________________________ It's fast, it's easy and it's free. Get MSN Messenger today! http://www.msn.co.uk/messenger