home bbs files messages ]

Just a sample of the Echomail archive

Cooperative anarchy at its finest, still active today. Darkrealms is the Zone 1 Hub.

   LINUX      Torvalds farts & fans know what he ate      8,232 messages   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]

   Message 5,311 of 8,232   
   Joaquim Homrighausen to Nelgin   
   Alternative(s) to ipset on OpenVZ   
   18 Dec 17 21:32:10   
   
    >>Does anyone know of an alternative to ipset for blocking IP ranges   
    >>of entire countries, that works with OpenVZ containers?   
      
    n> I wish...   
      
    n> I use fail2ban. OpenVZ containers have limited memory and you can   
    n> soon fill it up with an all the subnets. With fail2ban you can block   
    n> the offenders easily. I have a "permaban" chain for those repeat   
    n> offenders.   
      
   Well, you can have some nicely sized containers if you want, but putting 500   
   000 drops (or rejects if you like them better) in an IPTABLE chain is perhaps   
   not a wise thing for anyone, thus the need for ipset.   
      
   Permaban is a good idea, until an IP range is re-assigned to someone else of   
   course :), but then again, I think it's better to err on the inclusive side in   
   this case.   
      
   It annoys me that ISPs don't have this as a service, and I'm quite surprised   
   they don't actually. I can understand the fact that they don't want to   
   subscribe to something like Cyren or similar, but they could quite easily do   
   it on their own.   
      
      
    -joho   
      
   ---   
    * Origin: code.code.code (2:20/4609)   

[   << oldest   |   < older   |   list   |   newer >   |   newest >>   ]


(c) 1994,  bbs@darkrealms.ca