Syn Flooding

Internet access discussion, including Fusion, IP Broadband, and Gigabit Fiber!
13 posts Page 2 of 2
by kevinmcm » Thu Oct 11, 2012 1:41 pm
If you had tools to accurately log the attack you could file complaints with the network where they originated. Attacks violate the terms of service of nearly all providers. For those where they don't, firewalling their entire address space is a pretty good idea.

My DSL is slow as hell so I file complaints when my personal server is attacked. Attacks from Russia, Nigeria, and China go straight to the firewall but otherwise it's very effective. It's often a compromised server in a datacenter so the owner is very interested in fixing it. Make sure all details are provided in the logs - source address, destination address, protocol, and a timestamp with a time zone.
by cataha » Fri Oct 12, 2012 11:49 am
logankl wrote:Where would I be able to purchase a router that can perform this function? I'm at a loss at this moment and in dire need of assistance..
Cisco ASAs and Juniper SSG devices among others have this capability.
Enterprise-grade firewalls like the ASAs and SSGs do this but a free firewall package like pfSense will also do this. If you get 3rd-party firmware for popular consumer routers or build your own, obviously you need to spend time to build as well as learn their new behavior.
I would recommend PLANNING and DESIGNING your network efficiently will eliminate 60-80% of your current problems without needing to buy more hardware/software
cause by just buying other media it will not going to help you unless you really really really know what you are doing because from what i seen in a real world it could create a heavy burden on your DSL/FUSION, if otherwise you wouldn't have had it in a first place, it's like placing a bandage on a large wound and saying it's been cured completely cause i don't see it been open

Before you even going to consider buying or choosing any firewall keep in mind that " A firewall in a monitoring traffic directing/shaping tool no more no less"

Also if you finally want/will buy a firewall i would also recommend do a HEAVY research on ONE TYPE that suites your needs cause FIREWALLS ARE FULL OF HOLE either it's a ASA or SSG or any other brands that's out there, because just by looking at an attacker i could already determined if it's a scripted or wantabe or well knowledged or...... point of all this that your peace of safe haven could become somebodies zombi machine within matter of 1-3 minutes if you don't really know what you are doing.!
I hope that will steer you in the right direction as well as for a future users/readers
by kents » Tue Oct 16, 2012 2:55 pm
I use a SonicWall TZ100. Prevents and notifies of all the various attacks.
13 posts Page 2 of 2