OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: Dynamic firewall based on bandwidth usage ?

From: Peter Becker (peter.beckeroberkassel.de)
Date: Thu Oct 12 2006 - 02:11:51 CDT


>> So I have to block (or redirect) those
>> network abusers after a download limit (for ex : 1Gb per day)
>> for lets say 1day.

> iptables -A INPUT -p tcp --dport 80 -m quota --quota 1073741824 -j ACCEPT
> iptables -A INPUT -p tcp --dport 80 -j DROP

Hmmm...
With the IPtables-quota how do you block this IP for a given time?
And what does the 'leecher' prevent to change the IP address?
When I scent that there could be a limit - I would disconnect my DSL
and continue downloading with my new connected IP.?!
But I also don't have a better idea...

Kind Regards,
Peter