Re: blocking a string in a packet using ipfw

2006-09-15 Thread Julian Elischer
Oliver Fromme wrote: Willem Jan Withagen wrote: > Julian Elischer wrote: > > > Forgot to mention: 4.7-PRERELEASE :( > > > > ugh... no tables > > and 45000 lines will be bad. Not necessarily ... > Over that time I collected over 50.000 IP's which all ended up > in IPFW. :) The box (PIII, 750

Re: blocking a string in a packet using ipfw

2006-09-15 Thread Oliver Fromme
Willem Jan Withagen wrote: > Julian Elischer wrote: > > > Forgot to mention: 4.7-PRERELEASE :( > > > > ugh... no tables > > and 45000 lines will be bad. Not necessarily ... > Over that time I collected over 50.000 IP's which all ended up > in IPFW. :) The box (PIII, 750 Mhz, 512Mb) starte

Re: blocking a string in a packet using ipfw

2006-09-15 Thread Willem Jan Withagen
Julian Elischer wrote: Forgot to mention: 4.7-PRERELEASE :( ugh... no tables and 45000 lines will be bad. load an old PC with 6.2 and seet it up as a bridge with 2 interfaces. and use ipfw table to filter on the bridge If I could have easy access to the box, that would be the sollution. Bu

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Julian Elischer
Willem Jan Withagen wrote: Barney Wolff wrote: On Thu, Sep 14, 2006 at 03:46:12PM +0200, Phil Regnauld wrote: Willem Jan Withagen (wjw) writes: Now I'm pretty shure that ipfw does not stretch indefinitely to contain perhaps something like 100.000 ip-numbers (would be a nice test. :) )

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Julian Elischer
Willem Jan Withagen wrote: [ I guess I haven't been paying too much attention during ipwf class :( And I got the suggestion to try FreeBSD-net@ instead of security. But I'm not subscribed to this list, so please Cc: me. ] Hi, perhaps somebody could give some pointers. I received a call fr

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Gary Palmer
On Thu, Sep 14, 2006 at 05:14:55PM +0200, Willem Jan Withagen wrote: > I had several suggestions this direction. And it does help a little. > The math is however against me. > > I had over 50 request/sec for this file. Now if the virus uses anything > which leaves the connection open for regular

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Willem Jan Withagen
Oliver Fromme wrote: Gary Palmer wrote: > Willem Jan Withagen wrote: > > I received a call from a customer this morning that all of his websites were > > no longer on line. So After some resetting and more I turnout that there > > was a > > serious overload on his server. Over 500 clients

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Willem Jan Withagen
Barney Wolff wrote: On Thu, Sep 14, 2006 at 03:46:12PM +0200, Phil Regnauld wrote: Willem Jan Withagen (wjw) writes: Now I'm pretty shure that ipfw does not stretch indefinitely to contain perhaps something like 100.000 ip-numbers (would be a nice test. :) ) Actually, it should. I ha

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Willem Jan Withagen
Gary Palmer wrote: On Thu, Sep 14, 2006 at 03:29:14PM +0200, Willem Jan Withagen wrote: I received a call from a customer this morning that all of his websites were no longer on line. So After some resetting and more I turnout that there was a serious overload on his server. Over 500 clients c

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Oliver Fromme
Gary Palmer wrote: > Willem Jan Withagen wrote: > > I received a call from a customer this morning that all of his websites > > were > > no longer on line. So After some resetting and more I turnout that there > > was a > > serious overload on his server. Over 500 clients connected. (norm i

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Barney Wolff
On Thu, Sep 14, 2006 at 03:46:12PM +0200, Phil Regnauld wrote: > Willem Jan Withagen (wjw) writes: > > > > Now I'm pretty shure that ipfw does not stretch indefinitely to contain > > perhaps something like 100.000 ip-numbers (would be a nice test. :) ) > > Actually, it should. I have over

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Gary Palmer
On Thu, Sep 14, 2006 at 03:29:14PM +0200, Willem Jan Withagen wrote: > I received a call from a customer this morning that all of his websites were > no longer on line. So After some resetting and more I turnout that there > was a > serious overload on his server. Over 500 clients connected. (norm

blocking a string in a packet using ipfw

2006-09-14 Thread Willem Jan Withagen
[ I guess I haven't been paying too much attention during ipwf class :( And I got the suggestion to try FreeBSD-net@ instead of security. But I'm not subscribed to this list, so please Cc: me. ] Hi, perhaps somebody could give some pointers. I received a call from a customer this morning th

Re: blocking a string in a packet using ipfw

2006-09-14 Thread Phil Regnauld
Willem Jan Withagen (wjw) writes: > > Now I'm pretty shure that ipfw does not stretch indefinitely to contain > perhaps something like 100.000 ip-numbers (would be a nice test. :) ) Actually, it should. > So I'd > like to see if there is something to do with divert and some matching on a