Skip site navigation (1)Skip section navigation (2)
Date:      Tue, 17 Apr 2001 12:19:19 -0500
From:      "Terry Witherspoon" <t403403@hotmail.com>
To:        questions@freebsd.org
Subject:   Avoiding denial of service.
Message-ID:  <F134YKpDS7hx27kBncc00000132@hotmail.com>

next in thread | raw e-mail | index | archive | help

Hi,

I've built several name servers running BIND 8.2.3.
I allow SSL connections to port 800 on each where I'm
running a web server. I'd like to avoid denial of
service on the name servers. There are already
DOS attacks in neighboring networks but as yet they've
not hit me. I have been portscanned a couple of times.
I've a Cisco router with an access list for port 800.
What knobs can I change to reduce impact of DOS? I do
not manage the Cisco but the network guy would implement
any acl I ask for. SHould I do something there too? These
are important servers for maybe 10,000 users.

Thanks for any advice , TW

_________________________________________________________________
Get your FREE download of MSN Explorer at http://explorer.msn.com


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-questions" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?F134YKpDS7hx27kBncc00000132>