Bug 10489 - No rate limiting for REJECT targets
Summary: No rate limiting for REJECT targets
Status: CLOSED FIXED
Alias: None
Product: IPFire
Classification: Unclassified
Component: --- (show other bugs)
Version: 2
Hardware: unspecified Unspecified
: - Unknown - - Unknown -
Assignee: Michael Tremer
QA Contact:
URL:
Keywords:
Depends on:
Blocks: 10486
  Show dependency treegraph
 
Reported: 2014-03-03 08:57 UTC by Michael Tremer
Modified: 2014-05-10 17:04 UTC (History)
2 users (show)

See Also:


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Michael Tremer 2014-03-03 08:57:24 UTC
Like there is no rate limiting for LOG rules, there is also no rate limiting for REJECT targets.

This makes it easy to cause a DoS because of the (usually smaller) uplink can be saturated with ICMP error messages.