Flood and Bandwith Protection

Flood and Bandwith Protection

Secure Home | Search | About
 General Computer Security    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Flood and Bandwith Protection alex.cabana 03-14-2005
Posted by on March 14, 2005, 11:59 am
If you were  Registered and logged in, you could reply and use other advanced thread options
Hi!

I'm working for an ISP and I'm trying to find a solution to some real
annoying flood problems. I have to control the traffic over a Gig-link
(About 600mb/s). I tried with snort and it's nearly impossible.

Specific Action required: Block the destination IP (Yeah, own customer)
when he receive more than 3mb/s of traffic per minutes. Is there a
snort rule that allow that.. or anything else somebody is aware of ?


Here's a short draw of the network


(provider) --- Gig link --- Cisco 7114 Router --- Cable Modem Users
|
|
Snort Linux Box

Any help or suggestion is appreciated



Posted by T. Sean Weintz on March 15, 2005, 1:13 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
alex.cabana@cgocable.ca wrote:
> Hi!
>
> I'm working for an ISP and I'm trying to find a solution to some real
> annoying flood problems. I have to control the traffic over a Gig-link
> (About 600mb/s). I tried with snort and it's nearly impossible.
>
> Specific Action required: Block the destination IP (Yeah, own customer)
> when he receive more than 3mb/s of traffic per minutes. Is there a
> snort rule that allow that.. or anything else somebody is aware of ?
>
>
> Here's a short draw of the network
>
>
> (provider) --- Gig link --- Cisco 7114 Router --- Cable Modem Users
> |
> |
> Snort Linux Box
>
> Any help or suggestion is appreciated
>

Um, would it not make more sense to throttle things at the router? Or
maybe add a good bridging mode hardware firewall with GIG links that
supports rate limitting by destination IP address?


Similar ThreadsPosted
ICMP flood from inside firewall February 1, 2006, 2:21 pm
alt.crypt sporge flood continues -- ?? December 15, 2007, 9:48 pm
CD copy protection November 15, 2005, 2:10 pm
Copyright protection... HOW??? May 21, 2006, 3:44 am
Re: Best Protection for HomePC February 18, 2008, 3:02 am
Serious level HDD data protection May 11, 2004, 2:40 am
New concept in software protection October 7, 2005, 1:43 am
REVIEW: "Always Use Protection", Dan Appleman December 14, 2005, 1:58 pm
software protection techniques February 11, 2006, 6:14 am
Software copy protection March 1, 2006, 5:00 am

The site map in XML format XML site map

Contact Us | Privacy Policy