7

Is there a rule for iptables to limit the amount of SYN packets a /24 range of IPs can send?

view full story
linux-howto

http://askubuntu.com – How can I block entire C class IP blocks when they send too many SYN packets to my ubuntu 12.04 server? Example of what I see during a SYN flood attack: Each different IP only sends 1 SYN packet, so the firewall doesn't block it. But the range 192.132.209.* all together is sending a lot of SYN packets in a very small time period. (HowTos)