Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 14 Jun 2006 13:12:30 +0300
From:      "Vlad GALU" <vladgalu@gmail.com>
To:        freebsd-pf@freebsd.org
Subject:   Re: PF+ALTQ as Anti-DoS?
Message-ID:  <79722fad0606140312i569cf55dsc84b9cb17ce692bc@mail.gmail.com>
In-Reply-To: <44B619B7.9050100@int-evry.fr>
References:  <44B619B7.9050100@int-evry.fr>

next in thread | previous in thread | raw e-mail | index | archive | help
On 7/13/06, Florent Thiery <Florent.Thiery@int-evry.fr> wrote:
> Hi,
>
> I'm having trouble finding information related to the use of altq as DoS
> mitigation technique... Do you have any interesting pointers ?

   If you have enough memory, synproxy + max-src-states + max-src-conn
is a great triplet.

>
> Thanks in advance
>
> Regards
>
> FLorent Thiery
>
>
> _______________________________________________
> freebsd-pf@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-pf
> To unsubscribe, send any mail to "freebsd-pf-unsubscribe@freebsd.org"
>


-- 
If it's there, and you can see it, it's real.
If it's not there, and you can see it, it's virtual.
If it's there, and you can't see it, it's transparent.
If it's not there, and you can't see it, you erased it.



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?79722fad0606140312i569cf55dsc84b9cb17ce692bc>