• 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!

TOPIC: rsfirewall captured Squid ip addresses Instead

rsfirewall captured Squid ip addresses Instead 13 years 7 months ago #11358

as i speak right now, one of my site is under ddos attack but the rsfirewall doesn't seem to be able to identified that.

after some checking and i find that the rsfirewall is actually capturing the squid ip instead of the actual visitor ip address.

is there any way to handle the Squid in order for the rsfirewall to captured real ip addresses?

www.squid-cache.org/

Throw in suggestion. Thanks.
The administrator has disabled public write access.

Re:rsfirewall captured Squid ip addresses Instead 13 years 7 months ago #11359

  • alexp
  • alexp's Avatar
  • OFFLINE
  • RSJoomla! Official Staff
  • Posts: 2253
  • Thank you received: 180
Hello,

Most operating system have a built in DOS protection. RSFirewall! tries to protect against such types of attacks by verifying the user agent against a known list (or by a user agent absence).

It can only detect the end user that performs the request (in this case the actual DOS) - basically a proxy. What is beyond the proxy the server (the IP that is actually performing this) is rather out of reach.
Please note: my help is not official customer support. To receive your support, submit a ticket by clicking here
Regards,
RSJoomla! Development Team
The administrator has disabled public write access.

Re:rsfirewall captured Squid ip addresses Instead 13 years 7 months ago #11360

alexp wrote:
Hello,

Most operating system have a built in DOS protection. RSFirewall! tries to protect against such types of attacks by verifying the user agent against a known list (or by a user agent absence).

It can only detect the end user that performs the request (in this case the actual DOS) - basically a proxy. What is beyond the proxy the server (the IP that is actually performing this) is rather out of reach.

is this mean that, rsfirewall is useless for my situation where my site is hide behind the squid/proxy?
The administrator has disabled public write access.
  • 1

Read this first!

We do not monitor these forums. The forum is provided to exchange information and experience with other users ONLY. Forum responses are not guaranteed.

However, please submit a ticket if you have an active subscription and wish to receive support. Our ticketing system is the only way of getting in touch with RSJoomla! and receiving the official RSJoomla! Customer Support.

For more information, the Support Policy is located here.

Thank you!