overhauled nftables implementation of DDoS prevention solution
The template [1] works now both for a straight forward Tor instance as well as for machine hosting many Tor instances in parallel. Therere no dedicated firewwall rules per Tor instance. The memory foot print is reduced. And, to avoid wrong abuse complaints from an over-reacting IDS I re-implemented the existing solution [2] in nftables [3]. Will continue to maintain iptables and nftables implementations of the ruleset [4]. As of today metrics show few dozen blocked addresses at a couple of tiny VPS relays, but a high 3-digit number at a bare metal server hosting 5 relays, drop rate is about 40 p/s here. Much higher values were observed in the past. Feedback appreciated. -- Toralf [1] https://github.com/toralf/torutils/blob/main/nftables-ingress.conf [2] https://github.com/toralf/torutils/blob/main/ipv4-rules-egress.sh [3] https://github.com/toralf/torutils/blob/main/nftables-egress.conf [4] https://github.com/toralf/torutils#the-rule-set
participants (1)
-
Toralf Förster