Re: [tor-relays] High number of simultaneous connections from a single host

2018-02-01 Thread grarpamp
Re all the threads on this 'DoS' issue... Netflow analysis is often better for many this type of toplists than netstat / ss and other tools shipped with any given base OS. Even a proper tcpdump / packet filter log can be better. ___ tor-relays mailing

Re: [tor-relays] High number of simultaneous connections from a single host

2018-01-31 Thread Tyler Johnson
> > > > However I'm still interested in how to block this kind of abuse outside of > tor > itself. I'm looking to implement some iptables limiting and I'm wondering > how > the limits should be so that I don't deny normal tor traffic. > > Would a 10 connections per IP limit be OK? Should be higher

Re: [tor-relays] High number of simultaneous connections from a single host

2018-01-31 Thread zless
În ziua de miercuri, 31 ianuarie 2018, la 17:32:15 EET, Roger Dingledine a scris: > On Wed, Jan 31, 2018 at 05:21:38PM +0200, zless wrote: > > I was inspecting my node and just saw that it has a very high number of > > connections. > > > > It jumped from the normal 6000-7000 to more than 17000

Re: [tor-relays] High number of simultaneous connections from a single host

2018-01-31 Thread nusenu
> I was inspecting my node and just saw that it has a very high number of > connections. > > It jumped from the normal 6000-7000 to more than 17000 simultaneous > connections. > > Looking at the connections with `ss` I see some hosts with over 1000 > connections while the majority is usually

Re: [tor-relays] High number of simultaneous connections from a single host

2018-01-31 Thread Roger Dingledine
On Wed, Jan 31, 2018 at 05:21:38PM +0200, zless wrote: > I was inspecting my node and just saw that it has a very high number of > connections. > > It jumped from the normal 6000-7000 to more than 17000 simultaneous > connections. > > Looking at the connections with `ss` I see some hosts with

[tor-relays] High number of simultaneous connections from a single host

2018-01-31 Thread zless
Hello everyone, I was inspecting my node and just saw that it has a very high number of connections. It jumped from the normal 6000-7000 to more than 17000 simultaneous connections. Looking at the connections with `ss` I see some hosts with over 1000 connections while the majority is usually