[OpenAFS] 1.4.2 fileserver keep getting large number of blocked connections

Jim Rees rees@umich.edu
Wed, 1 Aug 2007 08:51:03 -0400


Todd M. Lewis wrote:

  Is there a way to tell the fileservers not to talk to clients below a 
  certain rev, or only allow reads? That should encourage them to upgrade. 
  Or leave. Not nice maybe, but if old clients can DoS your servers...

Not directly, I don't think, but you could write a script that would go
through the server log periodically and get the IP addresses of misbehaving
clients, then add them to a firewall rule.