Re: FreeBSD 7, bridge, PF and syn flood = very bad performance

From: Dag-Erling Smørgrav <des_at_des.no>
Date: Sat, 26 Jan 2008 21:56:24 +0100
Stefan Lambrev <stefan.lambrev_at_moneybookers.com> writes:
> Dag-Erling Smørgrav <des_at_des.no> writes:
> > Try "synproxy state" instead of "keep state".
> From man pf.conf - Rules with synproxy will not work if pf(4) operates
> on a bridge(4).

Hmm, why are you experiencing a SYN flood on a bridge?  I assume the
bridge is inside your network, and the attack comes from outside your
network, in which case you should stop it at the entry point.

DES
-- 
Dag-Erling Smørgrav - des_at_des.no
Received on Sat Jan 26 2008 - 19:56:33 UTC

This archive was generated by hypermail 2.4.0 : Wed May 19 2021 - 11:39:26 UTC