From owner-freebsd-security Mon Jul 15 19:33:39 2002 Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.FreeBSD.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 5F1AD37B400 for ; Mon, 15 Jul 2002 19:33:37 -0700 (PDT) Received: from mx1.dev.itouchnet.net (devco.net [196.15.188.2]) by mx1.FreeBSD.org (Postfix) with ESMTP id 59B3C43E64 for ; Mon, 15 Jul 2002 19:33:36 -0700 (PDT) (envelope-from bvi@itouchlabs.com) Received: from nobody by mx1.dev.itouchnet.net with scanned_ok (Exim 3.35 #1) id 17UI8v-00006F-00 for security@freebsd.org; Tue, 16 Jul 2002 04:32:49 +0200 Received: from shell.devco.net ([196.15.188.7]) by mx1.dev.itouchnet.net with esmtp (Exim 3.35 #1) id 17UI8v-00005y-00; Tue, 16 Jul 2002 04:32:49 +0200 Received: from bvi by shell.devco.net with local (Exim 3.33 #4) id 17UII0-0003SB-00; Tue, 16 Jul 2002 04:42:12 +0200 Date: Tue, 16 Jul 2002 04:42:12 +0200 From: Barry Irwin To: zhang jack Cc: security@FreeBSD.ORG Subject: Re: syncache testing Message-ID: <20020716044212.L4570@itouchlabs.com> References: Mime-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline User-Agent: Mutt/1.2.5i In-Reply-To: ; from jack_zhangcl@hotmail.com on Tue, Jul 16, 2002 at 02:24:32AM +0000 X-Checked: Scanned for any viruses and unauthorized attachments at mx1.dev.itouchnet.net X-iScan-ID: 383-1026786769-68587@mx1.dev.itouchnet.net version $Name: REL_2_0_2 $ Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org Hi I'm not overly familiar with the syncache code, but you _may_ be able to make use of the syncache mitigation by having your server sitting behind the BSD box, with traffic being natted. A solution that may work better is to have a reverse proxy of sorts running on the BSD system which proxies requests to your webservers. Barry On Tue 2002-07-16 (02:24), zhang jack wrote: > > Hi, > I am testing syncache on FreeBSD 4.6 stable,and it works fine, > but I found it *only* protect syn flooding of itself,can it act > as a gateway( or firewall ) to protect my www server? > can anyone help me? -- Barry Irwin bvi@itouchlabs.com +27214875177 Systems Administrator: Networks And Security iTouch TAS http://www.itouchlabs.com South Africa To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message