Skip to Content.
Sympa Menu

discuss - Re: [opennic-discuss] Killed an IP due to excessive usage

discuss AT lists.opennicproject.org

Subject: Discuss mailing list

List archive

Re: [opennic-discuss] Killed an IP due to excessive usage


Chronological Thread 
  • From: Julian De Marchi <julian AT jdcomputers.com.au>
  • To: discuss AT lists.opennicproject.org
  • Subject: Re: [opennic-discuss] Killed an IP due to excessive usage
  • Date: Wed, 29 Dec 2010 14:44:07 +1000
  • List-archive: <http://lists.darkdna.net/pipermail/discuss>
  • List-id: <discuss.lists.opennicproject.org>

Jeff Taylor wrote:
> Yeah we've run into dns amplification attacks in the past, and we're all
> aware that the IP's are spoofed. I run shorewall here, and have
> verified that I have enabled anti-spoofing in iptables, yet somehow
> these packets are still getting through. Maybe iptables is forwarding
> the packets to the DNS server before the anti-spoofing measures are
> checked? I don't know, but it's annoying...

IIRC, anit-spoofing is just protection against your own IPs....

--julian




Archive powered by MHonArc 2.6.19.

Top of Page