In addition to Weibo, there is also WeChat
Please pay attention
WeChat public account
Shulou
2025-02-27 Update From: SLTechnology News&Howtos shulou NAV: SLTechnology News&Howtos > Development >
Share
Shulou(Shulou.com)06/01 Report--
This article mainly explains "how to defend against SYN attacks by Linux". Interested friends may wish to have a look at it. The method introduced in this paper is simple, fast and practical. Let's let the editor take you to learn how to defend against SYN attacks by Linux.
1. Default syn configuration sysctl-a | grep _ syn net.ipv4.tcp_max_syn_backlog = 1024 net.ipv4.tcp_syncookies = 1 net.ipv4.tcp_synack_retries = 5 net.ipv4.tcp_syn_retries = 5tcp_max_syn_backlog is the length of the SYN queue. Increasing the length of the SYN queue can accommodate more network connections waiting for connections. Tcp_syncookies is a switch, whether to turn on the SYN Cookie function, this function can prevent some SYN attacks. Tcp_synack_retries and tcp_syn_retries define the number of retry connections for SYN and reduce the default parameters to control the number of SYN connections as little as possible.
Second, modify the syn configuration ulimit-HSn 65535 sysctl-w net.ipv4.tcp_max_syn_backlog=2048 sysctl-w net.ipv4.tcp_syncookies=1 sysctl-w net.ipv4.tcp_synack_retries=2 sysctl-w net.ipv4.tcp_syn_retries= 2, Add firewall rule # Syn flood attack (--limit 1 FORWARD s limit syn concurrency once per second) iptables-An INPUT-p tcp--syn-m limit-limit 1 ACCEPT # Anti-port scanning iptables-A FORWARD-p tcp--tcp-flags SYN ACK,FIN,RST RST-m limit-- limit 1Universe s-j ACCEPT # Flood prevention ping iptables-A FORWARD-p icmp--icmp-type echo-request-m limit-- limit 1Universe s-j ACCEPT 4, add boot boot and finally don't forget to write the commands in second, third and third parts to / etc/rc.d/rc.local
At this point, I believe you have a deeper understanding of "Linux how to defend against SYN attacks". You might as well do it in practice. Here is the website, more related content can enter the relevant channels to inquire, follow us, continue to learn!
Welcome to subscribe "Shulou Technology Information " to get latest news, interesting things and hot topics in the IT industry, and controls the hottest and latest Internet news, technology news and IT industry trends.
Views: 0
*The comments in the above article only represent the author's personal views and do not represent the views and positions of this website. If you have more insights, please feel free to contribute and share.
Continue with the installation of the previous hadoop.First, install zookooper1. Decompress zookoope
"Every 5-10 years, there's a rare product, a really special, very unusual product that's the most un
© 2024 shulou.com SLNews company. All rights reserved.