4 ms·
It clearly states that it's for TCP based attacks. TCP attacks eg. SYN floods is a real problem and this does help against most such attacks. Just as real as a
by NightlyDev 7y ago
It clearly states that it's for TCP based attacks. TCP attacks eg. SYN floods is a real problem and this does help against most such attacks.
Just as real as anything else...
- ce4 7y agoonly for DoS, not DDoS. i.e. if you omit the distributed from Denial of Service, then iptables will work. Not so when the attack exhausts either your bandwidth or your stack's filtering capabilities. it's easy to rent GBits of distributed attack bandwidth.
- StreamBright 7y agoMost modern Unixes have syn cookies. You do not necessarily need anything else.
- NightlyDev 7y agoYou still have to do some tuning and at least assign RX queues properly. You want to drop unwanted traffic before you start spending more cycles on it.