Linode Forum
Linode Community Forums
 FAQFAQ    SearchSearch    MembersMembers      Register Register 
 LoginLogin [ Anonymous ] 
Forum locked  This topic is locked, you cannot edit posts or make further replies.
Author Message
PostPosted: Wed Sep 24, 2003 4:46 pm 
Offline
Linode Staff
User avatar

Joined: Tue Apr 15, 2003 6:24 pm
Posts: 3090
Website: http://www.linode.com/
Location: Galloway, NJ
I deployed new "transparent" network filtering yesterday evening around midnight. The filtering falls into two categories, global filtering and Linode-specific filtering.

The global filtering is already activated on all the hosts. This filters most of the broadcast traffic, the HSRP messages, and UDP port 137 traffic.

The Linode specific filtering filters broadcast traffic, and ARP traffic not destined for your IP(s).

The Linode specific filtering is available on all the hosts except host1 and host2. These require new kernel features which would require a reboot of host1 and host2 (both have over 100 days uptime). For now, only the global filtering and the original filtering is available on host1 and host2.

For those not on host1 and host2, to take advantage of the new filtering rules you must reboot your Linode.

If you perform some tcpdumps, you should notice a huge improvement.

Thanks and Enjoy!

-Chris


Top
   
PostPosted: Sun Sep 28, 2003 8:54 pm 
Offline
Senior Newbie

Joined: Sat Sep 13, 2003 7:29 pm
Posts: 8
Website: http://bruggerink.com/~zow
Location: CA, USA
caker wrote:
The Linode specific filtering is available on all the hosts except host1 and host2. These require new kernel features which would require a reboot of host1 and host2 (both have over 100 days uptime). For now, only the global filtering and the original filtering is available on host1 and host2.


Ahh! Okay -- I was just running tcpdump to debug some stuff, so I was wondering what you were smoking there for a minute. This brings up an important point though: we all enjoy long uptimes, especially for the host nodes. What's more, I've certainly had Linux boxes enjoy uptimes of over a year, and I've heard of much longer. Yet, I'm sure that there will be a need to upgrade the host machines every now and then, so have you considered having some sort of scheduled maintanence window where we can plan on our nodes going down, take any appropriate precausions, and be ready to do whatever we need when the host comes back up? I'm thinking something really infrequent, like once a year or something.

Just a thought.

-"Zow"


Top
   
Display posts from previous:  Sort by  
Forum locked  This topic is locked, you cannot edit posts or make further replies.


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
RSS

Powered by phpBB® Forum Software © phpBB Group