[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] overhauled nftables implementation of DDoS prevention solution



The template [1] works now both for a straight forward Tor instance as well as for machine hosting many Tor instances in parallel. Therere no dedicated firewwall rules per Tor instance. The memory foot print is reduced.

And, to avoid wrong abuse complaints from an over-reacting IDS I re-implemented the existing solution [2] in nftables [3].

Will continue to maintain iptables and nftables implementations of the ruleset [4].

As of today metrics show few dozen blocked addresses at a couple of tiny VPS relays, but a high 3-digit number at a bare metal server hosting 5 relays, drop rate is about 40 p/s here. Much higher values were observed in the past.

Feedback appreciated.

--
Toralf

[1] https://github.com/toralf/torutils/blob/main/nftables-ingress.conf
[2] https://github.com/toralf/torutils/blob/main/ipv4-rules-egress.sh
[3] https://github.com/toralf/torutils/blob/main/nftables-egress.conf
[4] https://github.com/toralf/torutils#the-rule-set

_______________________________________________
tor-relays mailing list -- tor-relays@xxxxxxxxxxxxxxxxxxxx
To unsubscribe send an email to tor-relays-leave@xxxxxxxxxxxxxxxxxxxx