Ethical Hacking

Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package.
Computer Forensics Training at InfoSec Institute

Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors.




Network Security Focus-Linux
[Top] [All Lists]

Dynamic firewall based on bandwidth usage ?

Subject: Dynamic firewall based on bandwidth usage ?
Date: Sun, 08 Oct 2006 14:44:22 -0400
Hello,
I have a common problem but cannot find a solution.

My setup :
all servers are Redhat Enterprise 4
CISCO PIX in front on a HTTP load Balancer/failover (called a director in the L.V.S. jargon) that sends requests to 4 web servers (cluster setup based on Linux Virtual Server include in redhat cluster suite).


Now my prob :-)

From time to time users download our site and block all http connexion, and worst, use all our bandwidth. So I have to block (or redirect) those network abusers after a download limit (for ex : 1Gb per day) for lets say 1day.

Because of the director, I cannot use the apache2 mod_cband.

My first though is to look at the iptables on the director but I cannot find any information about that kind of setup.

Do you know if it is possible using build in linux tools(iptables ?).

If not, do you know some hardware appliance that could do that ?

Thanks !

<Prev in Thread] Current Thread [Next in Thread>