Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 6 Dec 2000 10:20:23 -0600
From:      Bill Fumerola <billf@mu.org>
To:        James Lim <jameslpin@pacific.net.sg>
Cc:        Sebastiaan van Erk <sebster@sebster.com>, freebsd-security@FreeBSD.ORG
Subject:   Re: rx list
Message-ID:  <20001206102023.M86825@elvis.mu.org>
In-Reply-To: <002801c05f55$0a492ac0$fa5e78cb@gchang>; from jameslpin@pacific.net.sg on Wed, Dec 06, 2000 at 03:20:40PM %2B0800
References:  <20001206081549.A49341@sebster.com> <002801c05f55$0a492ac0$fa5e78cb@gchang>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, Dec 06, 2000 at 03:20:40PM +0800, James Lim wrote:

> 
>             You could try increasing the maxusers to 512 and later increase
> your NMBCLUSTERS to prolly 50000. How much ram does your machine has as well
> as the CPU speed?  Btw i was wondering whether the new accept filter helps
> in DoS attacks.
> 
> options                ACCEPT_FILTER_DATA
> options                ACCEPT_FILTER_HTTP

It doesn't help all (most) DoS attacks, but it might help in the 'netkill'
type attacks (where many connections are opened to the machine and never used).

-- 
Bill Fumerola - security yahoo         / Yahoo! inc.
              - fumerola@yahoo-inc.com / billf@FreeBSD.org





To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20001206102023.M86825>