08.09.03
IPTables tips
Q: How to setup transparent Squid proxy.
A: iptables -t nat -A PREROUTING -i $INT_IFACE -p tcp –dport 80 -j REDIRECT –to-port 3128
Q: Iptables version of stopping syn flooding
A:
#Create syn-flood chain for detecting Denial of Service attacks
iptables -t nat -N syn-flood
#Limit 12 connections per second (burst to 24)
iptables -t nat -A syn-flood -m limit –limit 12/s –limit-burst 24 -j RETURN
iptables -t nat -A syn-flood -j DROP
#Check for DoS attack
iptables -t nat -A PREROUTING -i $EXT_IFACE -d $DEST_IP -p tcp –syn -j syn-flood
Bill Compton said,
June 4, 2007 at 3:33 pm
Hi Jim. Photos i received. Thanks