centos阻挡洪水攻击
缩短SYN-Timeout时间:
1 | iptables -A FORWARD -p tcp –syn -m limit –limit 1/s -j ACCEPT |
每秒最多3个syn封包进入表达为:
1 | iptables -N syn-flood |
设置syncookies:
1 | sysctl -w net.ipv4.tcp_syncookies=1 |
防止PING:
1 | sysctl -w net.ipv4.icmp_echo_ignore_all=1 |
拦截具体IP范围:
1 | iptables -A INPUT -s 10.0.0.0/8 -i eth0 -j Drop |