-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1
forwarded from one DNSBLer...
Another tip from the SBL folks:
Also, someone else mentioned that the top-level zone, "surbl.org" for example, may become the target. So that also needs 2ndaries.
- --j.
On Monday, April 19, 2004, 11:27:24 AM, Justin Mason wrote:
Thanks for checking around for us, Justin. Looks like pound is a reverse proxy for distributing web traffic to multiple behind-the-scenes web servers. It sounds like a generally useful program. We certainly could to something like that, and I could see how it would be important to an operation like openrbl which depends on web service to provide it's info out to folks.
My solution is a little cruder but hopefully effective: limit MaxClients to some low enough number that the bad guys can't DOS us through web requests. Currently I have our Apache MaxClients set to 100, but I may lower it to say a fairly low 50. May also bring up web service on another server and use simple round-robin DNS for load balancing. Key though is that web is of lesser importance to us than DNS service, so if we lose web, it's not as much of a big deal as it would be to folks like openrbl.
Another tip from the SBL folks:
Yes, if we can get some more secondaries signed on board, I may take the source servers out of the registration and delegation entirely (to hide them a little) and let the secondaries do all the DNS. Heck we could probably do that now. Maybe we'll combine it with some other changes mentioned below.
Probably goes without saying, but selecting a zone name that can be "end of lifed" when needed should be considered.
Also, someone else mentioned that the top-level zone, "surbl.org" for example, may become the target. So that also needs 2ndaries.
Yep, we now have secondaries for the top level zone surbl.org. All the secondaries of the SURBL subdomains are also secondarying the parent domain. It becomes much harder to DOS the parent domain because of that. Thanks secondaries!! :-)
Also I have some other strategies for some redundancy and DOS resistance that I will share with (at least) the secondaries once I get another server or two set up.
Cheers,
Jeff C.