[squid-users] Handling client-side request floods

From: Dan Charlesworth <dan_at_getbusi.com>
Date: Tue, 8 Jul 2014 11:17:52 +1000

Hey folks

So I support a bunch of Squid deployments and every so often I’ll get a call about a poor performance, or very large access logs files etc.

Oftentimes as soon as I crack open the access log I see there’s a handful of machines (sometimes just one) practically DoSing the proxy with failed requests (failing because the client app won’t comply with proxy authentication).

Here’s a recent example of one of these bugs from Google Chrome:
https://code.google.com/p/chromium/issues/detail?id=373181

So I just wanted to see if anyone had any advice or suggestions for dealing with this kind of thing. I’m guessing iptables would be the logical place to try and prevent it, but I wouldn’t know where to start with rate limiting in iptables…

Anyone care to share?
Received on Tue Jul 08 2014 - 01:18:07 MDT

This archive was generated by hypermail 2.2.0 : Tue Jul 08 2014 - 12:00:05 MDT