Skip site navigation (1)Skip section navigation (2)
Date:      Sun, 13 Dec 1998 16:21:55 +0800 (WST)
From:      Dean Hollister <dean@odyssey.apana.org.au>
To:        Rowan Crowe <rowan@sensation.net.au>
Cc:        freebsd-isp@FreeBSD.ORG
Subject:   Re: sendmail morons
Message-ID:  <Pine.BSF.4.05.9812131620110.15434-100000@odyssey.apana.org.au>
In-Reply-To: <Pine.BSF.4.01.9812131835450.4706-100000@velvet.sensation.net.au>

next in thread | previous in thread | raw e-mail | index | archive | help
On Sun, 13 Dec 1998, Rowan Crowe wrote:

> Note that I specified "machine performance issue". I'd rather have my
> server have an absolute known limit where it no longer accepts new
> connections rather than a steady decline as more and more sendmail
> processes appear with each new connection. Seeing a machine run out of
> swap space is not fun. ;\

If you're worried about performance, then limit the number of connections
right down to 10-20.

> This absolute limit could also be of use in something like a SYN flood
> attack. (Note that limiting to 30 is probably _way_ too low, that's just
> something I've started with. Still experimenting).

I disagree with your suggestion that 30 is too low. If anything, 30 is too
high.

> Also, adding in IPs requires periodic review of the database by a human.

You can block by class-c, btw, not just single ips.

Regards,

d.


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-isp" in the body of the message



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.4.05.9812131620110.15434-100000>