Re: [squid-users] Flooding squid

2006-04-10 Thread Henrik Nordstrom
mån 2006-04-10 klockan 15:08 +0200 skrev Michał Margula: > Hello! > > I have some trouble with new kind of flood targeted at proxy server. > One hosts creates thousands of new connections. Is there a way to > protect against that at squid level? I would like to avoid doing it with > netfi

RE: [squid-users] Flooding squid

2006-04-10 Thread Nolan Rumble
I have some trouble with new kind of flood targeted at proxy server. One hosts creates thousands of new connections. Is there a way to protect against that at squid level? I would like to avoid doing it with netfilter, because it is hard to guess acceptable limit of connections (browsers tend to

Re: [squid-users] Flooding squid

2006-04-10 Thread Michał Margula
Mark Elsen napisał(a): There is a : max_conn parameter, check it out ; in squid.conf.default. Exact name slips me for the moment M. I was thinking about something more sophisticated, because now I have: acl too-many-connections maxconn 500 http_access deny all t

Re: [squid-users] Flooding squid

2006-04-10 Thread Mark Elsen
On 4/10/06, Michał Margula <[EMAIL PROTECTED]> wrote: > Hello! > > I have some trouble with new kind of flood targeted at proxy server. > One hosts creates thousands of new connections. Is there a way to > protect against that at squid level? I would like to avoid doing it with > netfilter,

[squid-users] Flooding squid

2006-04-10 Thread Michał Margula
Hello! I have some trouble with new kind of flood targeted at proxy server. One hosts creates thousands of new connections. Is there a way to protect against that at squid level? I would like to avoid doing it with netfilter, because it is hard to guess acceptable limit of connections (brows