How to defend against SYN Flood tools under Linux
This article mainly introduces how to defend against SYN Flood tools under Linux, which has a certain reference value, interested friends can refer to, I hope you can learn a lot after reading this article, let the editor take you to understand it.
SYN Flood (SYN Flood) is a typical DoS (Denial of Service) attack. The effect is that the server TCP connection resources are exhausted and stop responding to normal TCP connection requests.
If you are under a SYN flood attack on the Linux server, you can set the following:
Reduce SYN- timeout: iptables-A FORWARD-p tcp-syn- m limit- limit 1Universe s-j ACCEPTiptables-An INPUT-I eth0-m limit- limit 1/sec-limit-burst 5-j ACCEPT up to 3 syn packets per second iptables-N syn-floodiptables-An INPUT-p tcp-syn- j syn-floodiptables-A syn-flood-p tcp-syn- m limit- limit 1qt s-limit-burst 3-j RETURNiptables-A syn-flood-j REJECT setting syncookiessysctl-w net .ipv4.tcp _ syncookies=1sysctl-w net.ipv4.tcp_max_syn_backlog=3072sysctl-w net.ipv4.tcp_synack_retries=0sysctl-w net.ipv4.tcp_syn_retries=0sysctl-w net.ipv4.tcp_syn_retries=0sysctl-w net.ipv4.conf.all.send_redirects=0sysctl-w net.ipv4.conf.all.accept_redirects=0sysctl-w net.ipv4.conf.all.forwarding=0sysctl-w net.ipv4.icmp_echo_ignore_broadcasts=1 prevents the ping command sysctl-w net.ipv4.icmp_echo_ignore_all=1 from blocking a specific IP range iptables- An INPUT-s 192.168.5.1 eth0 8-I eth0-j Drop thank you for reading this article carefully I hope the article "how to defend against SYN Flood tools under Linux" shared by the editor will be helpful to you. At the same time, I also hope that you will support us and pay attention to the industry information channel. More related knowledge is waiting for you to learn!