Re: LB as a first row of defence against DDoS

2015-06-25 Thread Shawn Heisey
On 6/24/2015 8:58 PM, Baptiste wrote: > That said, I'll write a new DDOS protection article once HAProxy 1.6 > will be released, since it embeds some new features which are > interesting on this topic. I look forward to it. Thank you for your diligence! > Concerning your demand, I don't understa

Re: LB as a first row of defence against DDoS

2015-06-25 Thread Baptiste
>> Thank you for everything you do. You are one of the unsung heroes who >> make the guts of the Internet possible. > > Hehe don't feel like you're exagerating a bit here ? :-) > > Willy nope. Baptiste

Re: LB as a first row of defence against DDoS

2015-06-25 Thread Willy Tarreau
Hi, On Wed, Jun 24, 2015 at 12:03:39PM -0600, Shawn Heisey wrote: > On 6/24/2015 11:12 AM, Willy Tarreau wrote: > > The problem with configs posted on a blog is that people blindly copy-paste > > them without understanding and then break a lot of things and ask for help. > > Baptiste takes care of

Re: LB as a first row of defence against DDoS

2015-06-24 Thread Baptiste
hi all, Sorry for not answering sooner, but you know, you say "I'll do it in a couple of minute", then you focus on something else, then you forget, then you say "I'll do it in a couple of minute", then :) First of all, such type of article takes a long time to write, to review, to fix, to t

Re: LB as a first row of defence against DDoS

2015-06-24 Thread Krishna Kumar (Engineering)
> On Wed, Jun 24, 2015 at 11:33 PM, Shawn Heisey wrote: I agree - the blog talks of handling multiple attacks individually, but what we are trying to understand is - "how can we handle multiple types of attacks in a single configuration". Not the exact configuration file, but the concept to imple

Re: LB as a first row of defence against DDoS

2015-06-24 Thread Shawn Heisey
On 6/24/2015 11:12 AM, Willy Tarreau wrote: > The problem with configs posted on a blog is that people blindly copy-paste > them without understanding and then break a lot of things and ask for help. > Baptiste takes care of explaining how things work so that people can pick > what they need. There

Re: LB as a first row of defence against DDoS

2015-06-24 Thread Willy Tarreau
On Wed, Jun 24, 2015 at 09:51:36AM -0600, Shawn Heisey wrote: > I was going to comment on the blog post so the author would see the > request to put together a complete config with multiple front ends and > back ends, with all of them using every one of the DDOS techniques > included on the blog po

Re: LB as a first row of defence against DDoS

2015-06-24 Thread CJ Ess
Someone posted a link to a really tricked out anti-ddos haproxy config not long ago, it might be interesting to you: https://github.com/analytically/haproxy-ddos On Wed, Jun 24, 2015 at 11:51 AM, Shawn Heisey wrote: > On 6/18/2015 4:32 PM, Shawn Heisey wrote: > > On 6/17/2015 9:29 PM, Krishna K

Re: LB as a first row of defence against DDoS

2015-06-24 Thread Shawn Heisey
On 6/18/2015 4:32 PM, Shawn Heisey wrote: > On 6/17/2015 9:29 PM, Krishna Kumar (Engineering) wrote: >> Referring to Baptiste's excellent blog on "Use a lb as a first row of >> defense >> against DDoS" @ >> >> http://blog.haproxy.com/2012/02/27/use-a-load-balancer-as-a-first-row-of-defense-against-

Re: LB as a first row of defence against DDoS

2015-06-18 Thread Shawn Heisey
On 6/17/2015 9:29 PM, Krishna Kumar (Engineering) wrote: > Referring to Baptiste's excellent blog on "Use a lb as a first row of > defense > against DDoS" @ > > http://blog.haproxy.com/2012/02/27/use-a-load-balancer-as-a-first-row-of-defense-against-ddos/ > > I am not able to find a follow up, if

LB as a first row of defence against DDoS

2015-06-17 Thread Krishna Kumar (Engineering)
Referring to Baptiste's excellent blog on "Use a lb as a first row of defense against DDoS" @ http://blog.haproxy.com/2012/02/27/use-a-load-balancer-as-a-first-row-of-defense-against-ddos/ I am not able to find a follow up, if it was written, on combining configuration examples to improve protect