Hardening network by setting priorities
Hello security-list! I'd like to implement the following: To avoid DDoS-attacks I'd like to set priorities for certain network-services. I once read an article on securityfocus.com about how to for example set up that http-traffic is more important than DNS-traffic. It's possible using the ipchains. But unfortunately I can't find that article anymore where this is explained. So I hope for your assistance with this problem. Does anyone have a good description on how to set priorities? Thanks in advance, A. Achtzehn -- -----BEGIN GEEK CODE BLOCK----- Version: 3.1 GCS/CM/IT/P d@ s: !a C++(+) UL++++$ P++ L+++(++++)@ E---- W+++ N+ o? K? w O- M- V- PS PE- Y+ PGP++ t+ 5 X+ R* tv+ b++ DI? D-- G> e@> h!> ------END GEEK CODE BLOCK------ See http://www.ebb.org/ungeek/ on details.
Hello security-list! I'd like to implement the following: To avoid DDoS-attacks I'd like to set priorities for certain network-services. I once read an article on securityfocus.com about how to for example set up that http-traffic is more important than DNS-traffic. It's possible using the ipchains. But unfortunately I can't find that article anymore where this is explained. So I hope for your assistance with this problem. Does anyone have a good description on how to set priorities?
I think you are talking about traffic shaping, which won't really stop a conventional DoS attack.
Thanks in advance, A. Achtzehn
Kurt Seifried, seifried@securityportal.com Securityportal - your focal point for security on the 'net
participants (2)
-
Andreas Achtzehn
-
Kurt Seifried