Limit concurrent connections from a single IP address
Open
- Dominant language
- No language data
- Stars
- 10
- Forks
- 5
- PR merge metrics
- No merged PRs in 30d
Description
>Draft CIS Benchmark 1.1.8
## Description
It might be worthwhile mentioning the following configuration parameters: limit\_conn limit\_conn\_zone (sets shared memory zone) They are used to limit the number of connections per IP address. https://nginx.org/en/docs/stream/ngx\_stream\_limit\_conn\_module.html
## Rationale
The traffic normally originates from a fixed set of IP addresses, belonging to the machines used to carry out the attack. As a result, each IP address is responsible for many more connections and requests than you would expect from a real user.
## Remediation
None provided
## Audit
None provided
Contributor guide
Assessment
This issue has not been assessed yet.