help-cfengine
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: error during copying files


From: Avi Green
Subject: Re: error during copying files
Date: Thu, 21 Jun 2001 20:11:29 -0400

Daniel,

"Multiple connections denied/spam shield" is a well-known warning
indicating that the activitiy of cfengine's spam control feature. 
According to the cfengine tutorial
(http://www.iu.hio.no/cfengine/docs/cfengine-Tutorial.html#Spamming%20and%20security),
cfengine clients are normally allowed to connect to the server only one
session at a time, "i.e. they must terminate and reconnect in order to
establish a new session. This is to prevent a possible attacker from
opening multiple sockets and never closing them, resulting in a denial
of service attack."

Here are some things you might try:
1. Remove the associated locks on /etc/cfengine.
2. Check your "IfElapsed" and "ExpireAfter" settings.
3. Check your "AllowMultipleConnections" setting.*

* AllowMultipleConnectionsFrom 
This variable should contain a list of IP wildcards to hosts which are
allowed simultaneous sessions on the server. Hosts which are not in this
list are allowed to connect only once, i.e. they must terminate and
reconnect in order to establish a new session. This is to prevent a
possible attacker from opening multiple sockets and never closing them,
resulting in a denial of service attack. Hosts IP's can be placed here
if they could have overlapping copy sessions (e.g. long backup transfers
which can run over time). This prevents the error message "Multiple
connections denied/spam shield". 
This replaces the AllowMultipleConnections boolean variable which
existed in version 1.5.4 (only). 

--Avi

 ======================================================
 = Avi Green :-) avi at sputnik7.com (-: 212 217-1147 =
 ========  Unix SysAdmin & System Specialist  =========

 http://www.sputnik7.com - chronic online entertainment
  http://www.epitonic.com - Hi Quality Free MP3 Music
     http://www.res.com - The Future of Filmmaking
 http://www.we-deliver.tv - Log on, order in, smoke out
         the best grasses for the online masses



reply via email to

[Prev in Thread] Current Thread [Next in Thread]