Re: Newbie needs basic help with reject rules

Chris Buechler <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
On Wed, May 25, 2011 at 3:40 AM, Andy Wodfer <[email protected]> wrote:
> Hi,
> I have my first m0n0wall installation up and running and it looks very good.
>
> I have set up things as following:
>
> wan (external ip)
>
> lan 10.0.0.1/24
>
> I have a webserver on the lan at IP 10.0.0.10. I have set up NAT. The server
> is being DDOS'ed by a few IP addresses on port 80 and I wan't to reject
> these IP adresses and all ports (source+dest).
>
> I'm a little confused about whether putting these reject rules on the WAN or
> LAN? I thought WAN was the correct place, but I still see traffic coming
> through. Any ideas?
>

If it's sourced from the Internet, rule goes on WAN. But don't use a
reject rule against a DOS of any type, use block. Reject will
exacerbate the issue as it'll cause the firewall to send back a
connection refused message for every packet.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.