Forum Discussion
Jose_Santiago_O
Nimbostratus
Jun 22, 2009Apache DOS and LTMs.
Hello,
Past week, the ISC team published some articles saying that there was some risk of DOS in Apache Servers:
http://isc.sans.org/diary.html?storyid=6601
http://isc.sans.org/diary.html?storyid=6613
In today's post the are stating:
"First of all, those running some load balancers or reverse proxies in front of their Apache installations should check if they are really vulnerable or not – it's possible that the proxy is not affected by this vulnerability."
So, the question is, Are my apache servers running (2.X) behind the big-ips affected of this issue?
Can anyone elaborate on this?
Regards,
Jose Santiago Oyervides.
- hoolio
Cirrostratus
Hi, - hwidjaja_37598
Altostratus
I think your apache servers behind BIG-IP are not affected. BIG-IP has Adaptive Reaping to protect DOS attack. Even though slowloris is not a TCP DoS but the equivalent of a SYN flood over HTTP, I believe this reaper will protect BIG-IP and the server behind from this attack. When BIG-IP starts running out of resource, it will begin closing idle connection. - Jose_Santiago_O
Nimbostratus
Ok, Thanks everyone for your help! - Jose_Santiago_O
Nimbostratus
Ok, Thanks everyone for your help!
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects