<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Sockstress mitigation on Linux using Shorewall</title>
	<atom:link href="http://www.ipsidixit.net/2009/09/16/sockstress-mitigation-on-linux-using-shorewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.ipsidixit.net/2009/09/16/sockstress-mitigation-on-linux-using-shorewall/</link>
	<description>A far off place</description>
	<lastBuildDate>Tue, 13 Jul 2010 15:07:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: sgroarke</title>
		<link>http://www.ipsidixit.net/2009/09/16/sockstress-mitigation-on-linux-using-shorewall/comment-page-1/#comment-3884</link>
		<dc:creator>sgroarke</dc:creator>
		<pubDate>Fri, 18 Sep 2009 09:35:55 +0000</pubDate>
		<guid isPermaLink="false">http://www.ipsidixit.net/?p=191#comment-3884</guid>
		<description>Thanks for the pointer, but I can&#039;t find much more!! I looked for an archive of the irc #shorewall but did not find one, so do not have further details. Feel free to point me at them - I want to give people accurate, good information.

Reviewing what&#039;s suggested, it&#039;s not clear how the Red Hat suggestion &quot;breaks things&quot;. Again, please set me right on that and I&#039;ll add the info here.

For my part, I&#039;ve added this change to two live systems. Both medium-busy, running a variety of services (not just web) and have seen no breakage.

Note that I did originally say:

&lt;blockquote&gt;Note that the exact values used in the rules are, as the Red Hat advisory points out, going to be site specific. However the values given are a pretty good starting (and for many of us, finishing) point.&lt;/blockquote&gt;

Anyway, if anyone can enlighten me, please do. I always listen to advice!</description>
		<content:encoded><![CDATA[<p>Thanks for the pointer, but I can&#8217;t find much more!! I looked for an archive of the irc #shorewall but did not find one, so do not have further details. Feel free to point me at them &#8211; I want to give people accurate, good information.</p>
<p>Reviewing what&#8217;s suggested, it&#8217;s not clear how the Red Hat suggestion &#8220;breaks things&#8221;. Again, please set me right on that and I&#8217;ll add the info here.</p>
<p>For my part, I&#8217;ve added this change to two live systems. Both medium-busy, running a variety of services (not just web) and have seen no breakage.</p>
<p>Note that I did originally say:</p>
<blockquote><p>Note that the exact values used in the rules are, as the Red Hat advisory points out, going to be site specific. However the values given are a pretty good starting (and for many of us, finishing) point.</p></blockquote>
<p>Anyway, if anyone can enlighten me, please do. I always listen to advice!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: karmapolis</title>
		<link>http://www.ipsidixit.net/2009/09/16/sockstress-mitigation-on-linux-using-shorewall/comment-page-1/#comment-3881</link>
		<dc:creator>karmapolis</dc:creator>
		<pubDate>Thu, 17 Sep 2009 17:01:13 +0000</pubDate>
		<guid isPermaLink="false">http://www.ipsidixit.net/?p=191#comment-3881</guid>
		<description>Checkout the #shorewall archives, we chatted about this today. bleve suggests using Limit: instead of this, because this example breaks things.</description>
		<content:encoded><![CDATA[<p>Checkout the #shorewall archives, we chatted about this today. bleve suggests using Limit: instead of this, because this example breaks things.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
