Hello All,
I am new to Astaro, and I install Security Linux v6 to my Dual Amd, 1Gb box for testing.
We are having syn attacks nearly everyday. Actually, the source was only one IP address so that I can block that IP from my router. But sometimes we miss the attacks so web server goes to slow down, and customers’ starts to bla bla.
So that I started to search a firewall and ids system and found Astaro. 2 of sleepiness nights, I successfully installed and configured Astaro. I set my entire packet filters rule. I configure ids, syn, and others.
And I started to wait a syn attack and yesterday night we had. But unfortunately, Astaro do nothing against to attack. I turned log on everything from syn. I see the packets passing.
I really need your help for blocking these syn attacks. I decrease the p/s rate to 10/10 and still some syn are passing.
What I found in my mind is, if there are a syn packets from X source to Y dest. passing Z packets in a second. This will be count as 1. And if there are A events in B seconds, block the source X for C seconds.
I hope I can express what I think.
Please, I need your urgent help.
Thanks.
This thread was automatically locked due to age.