Improve SYNPROXY documentation (#4800)
Add a bit more explanation on the prerequisites for SYNPROXY, based on @ktsaou instructions in #4782
Chris Akritidis committed
Nov 30, 2018 at 16:13 UTC
451c8c85410c9d32864a566264d418127d593cff
1 file changed
+1
-1
collectors/proc.plugin/README.md
+1
-1
@@ -219,7 +219,7 @@ SYNPROXY is a netfilter module, in the Linux kernel (since version 3.12). It is
219
220
The net effect of this, is that the real servers will not notice any change during the attack. The valid TCP connections will pass through and served, while the attack will be stopped at the firewall.
221
222
-To use SYNPROXY on your firewall, please follow our setup guides:
222
+Netdata does not enable SYNPROXY. It just uses the SYNPROXY metrics exposed by your kernel, so you will first need to configure it. The hard way is to run iptables SYNPROXY commands directly on the console. An easier way is to use [FireHOL](https://firehol.org/), which, is a firewall manager for iptables. FireHOL can configure SYNPROXY using the following setup guides:
223
224
- **[Working with SYNPROXY](https://github.com/firehol/firehol/wiki/Working-with-SYNPROXY)**
225
- **[Working with SYNPROXY and traps](https://github.com/firehol/firehol/wiki/Working-with-SYNPROXY-and-traps)**