Performance suggestion

1 post Page 1 of 1
Junior Member
Posts: 1
Joined: 11 May 2008, 17:49

Improve iptables searching.

1. Currently, IP searching is very slow. It would be nicer if chains are divided by IP block. For example, IP started with 1 will be in weblock_1, 96 will be in weblock_96, 255 will be in weblock_255. This way will help faster searching more IP limit will be increased.

2. If CSF monitor the number of url request per IP, and block a IP if the same url is repeatedly requested by the IP; this is almost the same as mod_evasive, but mod_evasive does not implement share resources between http process, it does not do the job well.

1 post Page 1 of 1