Iptables question : need help =)

This is a discussion on Iptables question : need help =) within the Linux Security forums, part of the System Security and Security Related category; Hi all, Is it somebody know if it is possible to use iptables rules to allow only N socket open ...


Go Back   Usenet Forums > System Security and Security Related > Linux Security

FAQ Members List Calendar Search Today's Posts Mark Forums Read
  #1 (permalink)  
Old 07-31-2004
mcd
 
Posts: n/a
Default Iptables question : need help =)

Hi all,

Is it somebody know if it is possible to use iptables rules to allow only N
socket open per user, or deny the connection to a new socket if N are
already open ?

Tanks a lot,
answer realy help me ;-)

Mike
mike@cnul.org


Reply With Quote
  #2 (permalink)  
Old 07-31-2004
Juha Laiho
 
Posts: n/a
Default Re: Iptables question : need help =)

"mcd" <mike@cnul.org> said:
>Is it somebody know if it is possible to use iptables rules to allow only N
>socket open per user, or deny the connection to a new socket if N are
>already open ?


As far as I know, there isn't such functionality. What it is that you're
attempting to achieve (so, what you're trying to achieve with this
limitation)?
--
Wolf a.k.a. Juha Laiho Espoo, Finland
(GC 3.0) GIT d- s+: a C++ ULSH++++$ P++@ L+++ E- W+$@ N++ !K w !O !M V
PS(+) PE Y+ PGP(+) t- 5 !X R !tv b+ !DI D G e+ h---- r+++ y++++
"...cancel my subscription to the resurrection!" (Jim Morrison)
Reply With Quote
  #3 (permalink)  
Old 07-31-2004
Peter O
 
Posts: n/a
Default Re: Iptables question : need help =)

"mcd" <mike@cnul.org> wrote in message news:<cefs43$9nk$1@news.tiscali.fr>...
> Hi all,
>
> Is it somebody know if it is possible to use iptables rules to allow only N
> socket open per user, or deny the connection to a new socket if N are
> already open ?
>
> Tanks a lot,
> answer realy help me ;-)
>
> Mike
> mike@cnul.org


Hi Mike,

please have a look at --limit and --limit-burst flags (iptables). By
using them on SYN packages you might be able set a policy that will do
something similar to what you want to achieve.

Cheers,
Peter
www.dialore.com
Reply With Quote
  #4 (permalink)  
Old 07-31-2004
Morten Isaksen
 
Posts: n/a
Default Re: Iptables question : need help =)

On Sat, 31 Jul 2004 10:47:02 GMT, Juha Laiho wrote:

> "mcd" <mike@cnul.org> said:
>>Is it somebody know if it is possible to use iptables rules to allow only N
>>socket open per user, or deny the connection to a new socket if N are
>>already open ?

>
> As far as I know, there isn't such functionality. What it is that you're
> attempting to achieve (so, what you're trying to achieve with this
> limitation)?


There is a module to iptables that can do that. Check for connlimit at
http://www.netfilter.org/patch-o-matic/pom-base.html.

It is not part of the standard kernel.

It is very useful to stop p2p users from makeing too many connections.

--
Morten Isaksen
http://www.aub.dk/~misak/
Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT +1. The time now is 06:10 AM.


Powered by vBulletin® Version 3.7.3
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.0.0