Re: max # of connections per IP ?

This is a discussion on Re: max # of connections per IP ? within the IPFilter forums, part of the System Security and Security Related category; Quoting Alessandro de Manzano (ale@unixmania.net): > I'ld ask you all some hints about a policy rule I ...


Go Back   Usenet Forums > System Security and Security Related > IPFilter

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 09-08-2003
Chuck Yerkes
 
Posts: n/a
Default Re: max # of connections per IP ?


Quoting Alessandro de Manzano (ale@unixmania.net):
> I'ld ask you all some hints about a policy rule I have to implement in
> my firewall.
>
> I'm currently using IPF 3.4.29 on a FreeBSD 4.8 box and now I've been
> told to limit number of connections for a single source IP.


Hmmm, ipf, afaik, doesn't do this.

Why? Because there is no good technical reason for it, really.

You've got a request coming from ISO layer 8 (the political layer)
to do something at layer 4.

In this situation, I might try to divine what the problem or threat
is that they believe this will address.

Note also that I can run mozilla and perhaps go to a bookmark that
opens 5 tabs and each tab opens 8 HTTP connections and that one
"go to bookmark" creates 40 TCP connections.

Is this wrong? no, it's well within the spec's of HTTP and TCP/IP.
Is this bad? Not really.


Could this cause problems? Sure, I could run out of TCP connections
on the firewall, but that's better handled by (1) a web proxy and
(2) tuning of the client.

If BANDWIDTH is a problem that too is best handled elsewhere.

This smells to me of a semi-technical person perceiving a solution
to a problem and mandating that when correct and implementable
solutions exist.

Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 10:55 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0