qemu-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-devel] [PATCH 6/6] vnc: track & limit connections


From: Gerd Hoffmann
Subject: Re: [Qemu-devel] [PATCH 6/6] vnc: track & limit connections
Date: Tue, 21 Oct 2014 11:35:06 +0200

  Hi,

> Yes. But I think it is not a big problem, when the REJECT_TIME is over,
> the good guys can connect vnc successfully immediately.
> Or maybe we just lock those guys with "the same Source IP address" ?

Better.  Question is whenever we really want implement those schemes
within qemu or leave that to the firewall to handle (connlimit comes to
mind, see "man iptables-extensions").

Doing it in qemu IMO only makes sense when using information the
firewall doesn't have.  With sasl enabled we can slow down login
attempts *per user* for example.

cheers,
  Gerd





reply via email to

[Prev in Thread] Current Thread [Next in Thread]