3 ms·
I don't know what request throttling solutions are available for nginx. But, for apache there are modules and scripts/code that can rate limit traffic and reque
by vabmit 13y ago
I don't know what request throttling solutions are available for nginx. But, for apache there are modules and scripts/code that can rate limit traffic and requests from specific IPs. Depending on the size of the botnet attacking, rate limiting requests by IP or network may have been a way to mitigate the DDoS effects. Again, depending on the specifics, you should be able to use iptables (if you're running Linux) to limit requests per source IP or IP range. The type of actions you can take with iptables are really quite robust.
I've had to deploy request rate limiting solutions in the past because of well meaning federated search mash-ups that included content from servers that I run.
Filtering by useragent seems to be a temporary solution. I think that's especially true since you've disclosed publicly that's what you're doing.
- daemon13 13y agoWith nginx you can easily rate-limit connections, requests and downloads (which you can throttle also). Can also do this by GeoIP - country, etc. No need for extra steps - this module shall be compiled and part of nginx-full package from nginx official PPA, if OP is using Ubuntu.