[Author Prev][Author Next][Thread Prev][Thread Next][Author Index][Thread Index]

[tor-relays] connlimit: better to use "DROP" or "REJECT --reject-with tcp-reset"?



For relay operators using iptables connlimit to mitigate DoS attacks (or increased load from new clients)​, is it better for the Tor network to use "DROP" rules, or should we use something like "REJECT --reject-with tcp-reset"?

_______________________________________________
tor-relays mailing list
tor-relays@xxxxxxxxxxxxxxxxxxxx
https://lists.torproject.org/cgi-bin/mailman/listinfo/tor-relays