Layer 2-4 DoS Protection
Apr 5, 2009What exactly does the DoS protection layer 2-4?
in which attacks are successful.?
What exactly does the DoS protection layer 2-4?
in which attacks are successful.?
3Tera's AppLogic could be the expeditor of a lot of small and medium dreams. I read the whopping 28 pages thread about TGL, it sure got my juices running. With enough time, the grid could evolve into something close to a Matrix (and hence the thread title).
Yet it seems it wasn't stable yet (at that time). And 3Tera and TGL were talking about features yet to come. So my question is:
Is their service stable yet?
Anyone else seeing packet loss / high latency? I was told that Savvis and or Layer3 are having some routing issues tonight.
View 4 Replies View RelatedI currently have a rack of gear in a nice colo. At first this colo was established to provide for some of my own equipment. However, in the past year or two I have had several customers express interest - so I have started reselling some colo space to them.
Currently I have three network feeds from the provider coming into my cabinet. I am about to add a 4th feed. All of these feeds have been added so that my customers could have a dedicated connection to plug into their hardware firewalls.
Since I am growing and about to add a 4th customer, I am now trying to figure out how to simplify this, and better provide for future growth. I am thinking that the best way would be to have one "feed" from the provider. Then I would bring that one feed into a layer three switch which I could use to break the feeds out to my customers. This would also allow me to measure the bandwidth being used by each customer and bill them accordingly.
Does this sound right to you all? Also - any recommendations on a good layer-3 switch?
From the real experience, how many mbps can it process in layer3 mode with 10-20 VLANs?
View 8 Replies View Relatedi have two servers colo on the IDC,
i want to search for a Layer 2 Switch for them,
the bandwidth we use now is about 5-10Mb only.
i hope the switch is reliable,but not expensive,
i do not need a lot of feature,just reliable for the connection for my service.
i find some cheaper switch,like d-link,ProCurve,
Is there a colo provider that has a free private network for use between their locations, similar to what SL has for their dedicated servers between facilities? They have 10GigE between their locations, with free unlimited usage.
We have around 40 servers now, and colo would really make sense, but we are doing multicasting stuff so we really need a backend network to support our services, as well as many locations for better delivery quality.
I'm investigating "suspects" that could be used in a server access environment. My requirements are:
*24 or 48 10/100/1000 Mbps Ports
*Atleast 2 x 1000Mbps uplinks (fiber preferred)
*SNMP-enabled for remote bandwidth polling @ ports and uplinks
*Simple Layer 3 allowing for per port rate limiting
VLAN creation support would be a plus, but not required
The switch needs to be able to handle ~1000Mbps of constant usage
I would be open to using non-Cisco switches as well.
I am looking for some good ddos protection providers, via protected dns. I've searched on internet, but most of them are really expensive.
Please tell me some ddos protection providers what could help me.(gige is too expensive btw).
And I found some ddos protection scripts. How can a script protected a server from ddos? A sript like CSF or DDoS deflate?
Hey guys If there was a way to have the ips of the dedi change constantly would this help prevent ddos attacks or would there be no difference if the domain was being attacked.
View 2 Replies View Relatedi'am looking for a software based ddos protection,some one know something for try to mitigate a ddos or help to get the server rock a solid?And i need to know too where i change the DNS(vhost) of my DEDICATED server.
View 4 Replies View Relatedso a guy I know runs a site, it's being hit very hard with a DDoS attack. He's spending about 500 /month to keep his site online. He's using ServerTech, but for the last few days, it's been offline and they have been non-responsive for the most part. I'm guessing they just don't know what to do.
Do you guys have any recommendations for any DDoS protected hosting? He doesn't really want to pay more, if he doesn't have to.
one of my server were hit by massive ddos syn atack. target was port 80-apache
i am running centos 5 in xen vps iptables were strong with syn filtering and limit
but...what can do?
if any of you could recomened a ddos prottected vps that allows ircd to be run im curentley in process of waiting for setup from sharktek but there slow response /setup time is making me wonder if its worth it please post your recommendations here then i can start my own reasearch from your list
View 11 Replies View RelatedAs we prepare to ramp up new networks, we are looking at different network attack protection devices such as Intruguard.
I am interested in input on other devices out there, or ideas using devices to protect against flood attacks and DDOS on a network that is under a gig in speed (100-200 Mbps).
Is bound to happen to my server one day or another (get attacked). So I need help deciding whether to get a DDoS protection server now or later. Or pay as I go (I'll explain this in a bit).
First of all I am considering getting this because I want to use this server to hide the real source where people are downloading from. People connect only through FTP server and download. Of course if I give the real IP away I am subject to attack at anytime from anyone.
I think if I buy a server somewhere else and have people connect to there then that server will connect to the real server if I was to get attacked the server I bought "somewhere" else would only get attacked which would or would not be protected by a that special company who protects for these kind of things.
Only downside so far is I have been able to have the method above done. A person connects from one server which connects to the real server they will be downloading from BUT I use up to 2x bandwidth. Because when someone requests a file from server A...server B sends to server A then sends back to the user requesting it. A process that well works but anyone know if instead of sending back to Server A it will go directly to the user without exposing any info on the real server?
When I meant "pay as you go" I mean have a server with a DDoS protection company but don't get any protection until it happens rather than waiting on the last minute before switching to them (like adding new users now but those users knowing the real source).
These "users" downloading do about 106GB average. So you can see how big a downside is having to use 2x of bandwidth from the method I know above. The companies I am on do not have DDoS protection that I know of so I am forced to look for external companies to use to connect to the real source.
-So far everyone knows the real source IP but that is because I trust them. Anyone else is waiting to get on it and me looking for ways to put them on.
//hopefully you enjoyed my big paragraphs.
-And what kind of "protection" would I need if only FTP is being used since there is "specialized" kind of filtering on attacks.
I was located in modvps.com, but I was asked to find another hosting because of DDoS attacks on my VPS.
Quote:
Hello,
Please move your accounts to some other hosting company. Let us know if you need any further assistance.
Regards,
Technical Support
I need:
DDoS Protection
RAM: 512 mb - 1024 mb
CPanel/WHM
10-30GB Disk Space
200-300 GB Transfer
60-70$...
Is there a way to enable hotlink protection so that when I edit a page from my computer the pictures from the server display from my server but my site is still protected from other hotlinking. My intent is to make it easier for someone to edit there page.(i know I could just reupload image files but I was trying to think of a way to make it easier for someone else) I thought adding my ip address to the cpanel hotlink protection enabler would do the trick but it hasn't.
View 4 Replies View Relatedwanting to password protect a directory and all FILES and DIRECTORIES under it as well.
I have tried the password protection system in plesk, simply put it doesnt work, sometimes it just doesnt restrict any access and the files can still be downloaded / accessed, and sometimes it asks for a password but even if typing the correct info it sais its a wrong password.
each time i setup the p/w i do it the exact same way, but its random about when it works and when it doesnt.
So, i tried the simple .htaccess way, and i still get the same problem. Can someone reccomend something to me? maybe a free php script that can do this? i need something fairly secure, doesnt need to be some super duper crazy script but at least so people cant just download the file containing the passwords and then they have access.
I have a plesk panel and i had a look for hotlink protection but unfortunately couldn`t find the proper option.
I guess there is a hotlink protection at windows version of plesk but not at linux one. I have a linux server.
Also i have a question about hotlinks also, one of my customer has a site that it uses too much bandwith like 600 gb at a month. It is an education related site and site is html.
And i am having some high load issues. When i check apache-status it shows %90 of the connections for that site. But i cant be sure that if it site really makes high load on server because like i told site is html. Also would like to know if server get s load for example if visitor wants to download something from site.
Because visitors are usually downloading zip, mp3 and those kind of files and i dont know if that many download cause the high load.
Also will it reduce the load of the server if i put hotlink protection to that site because of chance for other sites to leech files from this site?
Edit : If there isn`t any option for hotlink protection at Plesk panel how can i enable hotlink protection. Maybe using htaccess, but i would be glad if you can provide hotlink protection code also
Anybody have good experiences with some software based Apache 2.2 ddos protection. Im trying to find something similar then mod_evasive.
It's just that evasive won't work with Apache 2.2. It actually works, but it does not do what it is supposed to do.
Have tryed many different configuration, but it just won't do it.
After Googling i found out that many have suffered same kind of experiences with mod_Evasive and Apache2.2
I guess it is not working cos we got Peruser there. http://www.telana.com/peruser.php
Means that there is many differend child processes and evasive don't share data between childs.
So suggest me something. This is coming on prodution server with hundreds of domains so it has to be stable, fast and rock solid.
I have a budget of $20 monthly. I want to get a VPS, 500+ram, 15+gb, DDOS protection, managed, cpanel preferred. Which BIG webhost do you guys recommend? The webhost need to be big. Forget the small webhost, I am having a horrendous experience with a small webhost right now, and desperate for a change for better service, and quality.
View 14 Replies View RelatedI am interested in a VPS package, but that one doesn't have DDoS protection from the server side. Is it a really bad advantage? I am constantly hearing about DDoS attack that takes down the site. If it is not offered fromthe Server End, is there anything the user can do to protect/prevent from DDoS attack? Like..is DDoS protection solely from server provider only?
View 2 Replies View RelatedDoes anyone know of any virus protection software that will work with Cpanel. Actually it probably doesn't have to work with Cpanel.. but here is my situation..
I have a lot of people uploading PDF’s and Word docs to our MySQL database, for other people to download. So far I have been downloading the files to my computer first and scanning them, then approving them. it would be nice if I can automate this check some how. I'm wondering of anyone out there does this sort of thing with the dedicated servers they run. Maybe just putting virus software on the server is good enough.
I was looking for a basic DoS protection against scriptkiddys.
I heard nginx is better as apache against DoS attacks.
if your web host has some hardware ddos protection and i'm assuming it blocks the ip address/addresses of a DDOS attack, will it Unblock that ip address/addresses after a certain amount of time?
Because a person's computer may unknowingly be part of a botnet that does a ddos attack, and that innocent person won't be able to access the server if their ip address is not unblocked by the ddos hardware right?
I know I am getting SYN flooding and server comes on KNEE and somehow I see that MY CSF is not helping me when I really need it.
I see that CSF is just not blocking those IPs despite of more than 500 requests sent per second from those IPs. I can manually block them but I want CSF to block them automatically as it is supposed too.
HERE Is my CSF config: .....
Just thought I would post some information regarding a "backdoor" in which many web hosts fail to secure.
If you run WHMCS on the same server you setup client accounts, someone can simply sign-up and easily access your WHMCS configuration file.
All it takes is for the user to upload a shell script and execute the following command:
Quote:
cat /path/to/your/configuration.php-file/
From there, they can access your configuration settings (MySQL) and create an administrator account.
How to fix:
If you have already disabled functions in your php.ini file, then you should be fine. If not, you will want to disable the following functions in your php.ini file:
Quote:
disable_functions="exec, shell_exec, proc_close, proc_open, pope n,system, passthru, escapeshellarg, escapeshellcmd, symlink"
You may want to enable safe_mode as well, but this may cause issues for certain scripts.
I would highly recommend installing mod suPHP and php cgi or simply move your "master" account to a different server.
What are some of the companies that have good, proven DDoS protection? Regardless of price.
I have done some searching, but wanted some outside opinions.
I know of:
www.gigenet.com
www.blacklotus.com
Does anybody know which rules should be used to allow hotlinking of files with *_thumb* in their file name and block hotlink of all other files?
View 2 Replies View RelatedCan you suggest some other places one can get good ddos protection?
View 0 Replies View Related