Gentoo Forums
Gentoo Forums
Gentoo Forums
Quick Search: in
Denial of service: how to prevent?
View unanswered posts
View posts from last 24 hours

 
Reply to topic    Gentoo Forums Forum Index Networking & Security
View previous topic :: View next topic  
Author Message
cazze
Apprentice
Apprentice


Joined: 26 Mar 2003
Posts: 155
Location: Brussels - Belgium

PostPosted: Mon Apr 11, 2005 3:41 pm    Post subject: Denial of service: how to prevent? Reply with quote

Hi,

i don't know if i should post this here or in the programming forum, but here it comes.

I have a program who is listening on a udp port. The server on wich it runs, is behind a firewall. I use port forwarding on the firewall to the server.
Is there a way to prevent someone flooding the port with bogus packages so that the service becomes unavailable for the users who send interesting traffic?
Is a vpn tunnel between the client and the firewall a solution and how should i configure it if it is?
I'm sort of lost here on this. I think i don't understand enough the working of Dos attacks to prevent them.

kammicazze
_________________
Required: Windows 95 or better, so i installed Linux!!!
Back to top
View user's profile Send private message
cokey
Advocate
Advocate


Joined: 23 Apr 2004
Posts: 3355

PostPosted: Mon Apr 11, 2005 3:47 pm    Post subject: Reply with quote

Most intelligent routers will figure out if a DDOS attack is being performed and drop and ban any packets from a certain address if that happens so you may need a better router. Or am I misunderstanding the situation?
_________________
https://otw20.com/ OTW20 The new place for off the wall chat
Back to top
View user's profile Send private message
Sachankara
l33t
l33t


Joined: 11 Jun 2004
Posts: 696
Location: Stockholm, Sweden

PostPosted: Mon Apr 11, 2005 5:17 pm    Post subject: Re: Denial of service: how to prevent? Reply with quote

Use "TCP syncookies". You'll find it in the kernel options...
_________________
Gentoo Hardened Linux 2.6.21 + svorak (Swedish dvorak)
Back to top
View user's profile Send private message
cazze
Apprentice
Apprentice


Joined: 26 Mar 2003
Posts: 155
Location: Brussels - Belgium

PostPosted: Mon Apr 11, 2005 6:29 pm    Post subject: Reply with quote

@Sachankara: TCP syncookies for UDP packets?

@cokehabit: You should probably be right, but how can a router make the difference between UDP audio stream packets over that port and a bogus data stream stream? The data over the port isn't a known protocol :(
_________________
Required: Windows 95 or better, so i installed Linux!!!
Back to top
View user's profile Send private message
Display posts from previous:   
Reply to topic    Gentoo Forums Forum Index Networking & Security All times are GMT
Page 1 of 1

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum