感觉网站变快了不少,爽 :)
@
liwei 小dos可以,按这次流量估计是ddos,不知 @
livid 有没有试过 hardening kernel 后的防护力
/etc/sysctl.conf
# Increase resources to mitigate SYN floods
net.ipv4.tcp_max_syn_backlog=1280
# Enable TCP syncookies to fight TCP synflood attacks
net.ipv4.tcp_syncookies=1
# Decrease tcp fin connection timeout (60) or reuse it
net.ipv4.tcp_fin_timeout = 15
net.ipv4.tcp_tw_recycle = 1
# Enable source validation by reversed path
net.ipv4.conf.all.rp_filter = 1
net.ipv4.conf.default.rp_filter = 1
不过也没用,一般给VPS分配的带宽也就 40~100Mbps 左右,就算系统能顶住也得被K出去#_#