Next: , Previous: , Up: system Statement Definition and Usage   [Contents][Index]


A.1.2.14 rate-limit-slip

As attacks using DNS/UDP are usually based on a forged source address, an attacker could deny services to the victim netblock if all responses would be completely blocked. The idea behind SLIP mechanism is to send each Nth response as truncated, thus allowing client to reconnect via TCP for at least some degree of service. It is worth noting, that some responses can’t be truncated (f.e. SERVFAIL).

Default value: 1