Skip to content

Latest commit

 

History

15 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

Eldewrito Anti DDOS

Some hardening tips for your eldewrito server(or any game server really).

Limit the number of connections from a single address on the game ports

for i in {11774...11777}; do 
    iptables -A INPUT -p tcp --syn --dport $i -m connlimit --connlimit-above 3 -j DROP;
done

Mass block known malicious ip addresses and ranges using a firehole netset (works with any ip list). Firehol level1 can be found here: https://github.com/firehol/blocklist-ipsets/blob/master/firehol_level1.netset

filename='firehol_level1.netset'

while read p; do
    ip route add blackhole $p
done < $filename

Remove the ip block list

filename='firehol_level1.netset'

while read p; do
    ip route del $p
done < $filename

Enable Syn Cookies

vim /etc/sysctl.conf

Add the following line:
net.ipv4.tcp_syncookies = 1

Reload with:
sysctl -p

Protect ssh with fail2ban

apt-get install fail2ban

Disable ssh root login

vim /etc/ssh/sshd_config

Add:
PermitRootLogin no

Restart sshd:
sudo service ssh restart

Setup basic firewall with UFW

sudo apt install ufw

sudo ufw allow 22

sudo ufw allow 11775:11777/tcp
sudo ufw allow 11774:11774/udp

sudo ufw enable

About

Some hardening steps for your eldewrito server.

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors