Thread: DDoS
View Single Post
  #15  
Old 11-29-2009, 04:47 PM
cadiz cadiz is offline
Kobold

cadiz's Avatar

Join Date: Nov 2009
Location: Dublin, Ireland
Posts: 118
Default TCP FIltering Idea

Have you guys thought about implementing something like a SYN proxy like what OpenBSD's PF offers?

This would basically proxy your TCP handshakes, allowing you to set thresholds and discard bad packet and requests (or not respond to them all together).

http://www.openbsd.org/faq/pf/filter.html#synproxy

TCP/5998 ---> <openbsd pf box> ---> eq server

Furthermore, you could inspect packet headers with SPI but this would be a bit cpu intensive.

Just an idea, it may not be feasible given your resources (additional machine/staff know-how/ease of setup). I've used OpenBSD PF with great success in many enterprise scenarios, you can even use 'CARP' to load balance among several firewall nodes.

http://www.openbsd.org/faq/pf/carp.html
__________________
Prexus: (00-04) <Clan nan Dreolan>
Cadiz (70 NEC) epic 1.0
Grumplescratch (65 WAR) epic 1.0
Tzartole (62 MNK) epic 1.0