LiteSpeed Technologies
Download Download     Blog Blog     Wiki Wiki     Forum Forum     Store     Contact Contact    

Go Back   LiteSpeed Support Forums > LiteSpeed Web Server > General > I'm behind SYN FLOOD with Spoofed IP'S

Reply
 
Thread Tools Display Modes
  #11  
Old 06-09-2012, 10:50 AM
midulc midulc is offline
Member
 
Join Date: Jun 2012
Posts: 15
Default Butnothing

Have optimized ALL centos configuration based on all I could find on internet and the ddos still gets my ded down.
The cpu use goes full and the conection usage to 250 mbps. There are lots of SYN_rECEIVED packets.
There's no way to stop this... What to do?
Internet connection is 10gbps so that's not the problem, it's that cpu usage goes to the limit.
Reply With Quote
  #12  
Old 06-09-2012, 08:52 PM
NiteWave NiteWave is offline
LiteSpeed Staff
 
Join Date: Sep 2009
Posts: 2,292
can you identify which process has high CPU usage, by "top -c" etc?

ddos usually last short time only, is your website DDOS'd continuously?
Reply With Quote
  #13  
Old 06-09-2012, 09:12 PM
midulc midulc is offline
Member
 
Join Date: Jun 2012
Posts: 15
Default Continuously

It's continuously behind a DDOS. I can't run that command as now the dedicated got blocked for so many traffic
Reply With Quote
  #14  
Old 06-11-2012, 02:16 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,390
again, you can order "Advanced Anti-DDoS Setup"
https://store.litespeedtech.com/store/cart.php?gid=5
Reply With Quote
  #15  
Old 06-11-2012, 03:15 PM
midulc midulc is offline
Member
 
Join Date: Jun 2012
Posts: 15
Default Finally solution

I even set up the iptables to block ALL ALL THE REQUESTS ALL, iptables -i INPUT -j DROP and still got behind attack!

Conclusion: External firewall is the only solution.
Reply With Quote
  #16  
Old 06-11-2012, 03:21 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,390
or you can try our free service.

http://www.litespeedtech.com/litespe...y-service.html
Reply With Quote
  #17  
Old 06-11-2012, 05:55 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,390
Quote:
Originally Posted by midulc View Post
...

Conclusion: External firewall is the only solution.
This is not necessarily true. Really depends on how iptables is setup.
Reply With Quote
  #18  
Old 06-21-2012, 10:45 AM
semprot semprot is offline
Member
 
Join Date: Apr 2012
Posts: 41
Quote:
Originally Posted by webizen View Post
again, you can order "Advanced Anti-DDoS Setup"
https://store.litespeedtech.com/store/cart.php?gid=5
I wonder if it is the same one as "LiteSpeed Anti-DDoS Appliance" here ?
http://www.litespeedtech.com/litespe...appliance.html
__________________
I use litespeed
Reply With Quote
  #19  
Old 06-21-2012, 01:30 PM
webizen webizen is offline
LiteSpeed Staff
 
Join Date: Oct 2010
Posts: 2,390
Quote:
Originally Posted by semprot View Post
I wonder if it is the same one as "LiteSpeed Anti-DDoS Appliance" here ?
http://www.litespeedtech.com/litespe...appliance.html
They are different. LiteSpeed Anti-DDoS Appliance is more advanced dedicated device to handle larger attacks.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -7. The time now is 12:09 AM.



- Archive - Top
© Copyright 2003-2011 LiteSpeed Technologies, Inc. All rights reserved. Privacy Policy.