Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Re: apache 'deny from' vs iptables

From: Steve Suehring <debisp2007(at)braingia.org>
Date: Sat Feb 02 2008 - 19:49:13 EST


On Sat, Feb 02, 2008 at 05:55:01PM -0500, Dan MacNeil wrote:
> Would things be faster with iptables ?

Yes, I would think so. By denying them at the Apache level, a TCP connection must be setup whereas with iptables the connection would be denied prior to getting to the Apache server. By denying it at the kernel level (with iptables) you're saving Apache from having to deal with the request at all.

You might also look for patterns in the IP addresses to find out if there are subnets that can be denied with iptables rather than individual addresses. Obviously doing so can have unintended side effects if the subnet is too wide and you deny legitimate requests, so it's a trade-off.

Also, you might want to analyze the IPs that are being denied. Over time some of those entries are likely to become stale as the IP address owners change. You'll probably notice some patterns of IP addresses or networks that are always doing something bad while others are just one time hits.

Steve

-- 
To UNSUBSCRIBE, email to debian-isp-REQUEST@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmaster@lists.debian.org
Received on Sat Feb 2 19:50:14 2008

This archive was generated by hypermail 2.1.8 : Wed Mar 19 2008 - 06:52:42 EDT


Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library