SYN flood on [2.0.33]

Pawel S. Veselov (vps@phoenix.math.spbu.ru)
Sun, 1 Mar 1998 20:38:07 +0300 (MSK)


Hello, All !

There was recently a following problem :

Kernel stop responding on 25th port, believing all income connections
are flood. There are a lot "Warning: possible SYN flood from ..." messages.
All of them came from mail relays, e.g. nic.funet.fi, portcullis.itis.com,
etc, including our local mail relays. I don't believe this was a real attack.

There are also a lot of "validated probe" messages , but I never could
reach 25th port telnetting on it. I got "connected" once, but nothing followed.
In other cases connection failed on timeout.

reboot healed this, of course.

So the question is what made such things to happen, how I can prevent this
or correct the problem without reboot()ing.

Thanx beforehand.

Bye.

--
Man is the measure of all things.
		-- Protagoras

--
    With best of best regards, Pawel S. Veselov (aka Black Angel)
                   Internet e-mail : vps@mindless.com
    Web page : http://www2.math.spbu.ru/~vps/ | ICQ UIN : 5252265

- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.rutgers.edu