Skip to main content

Concurrent connections causing high load

Comments

2 comments

  • cPRex Jurassic Moderator
    Hey there! It sounds like when the DoS happens it's just too much for the server to handle. It would be better to speak with your hosting provider or datacenter to see if they have any external solutions they can provide. If not, you may need to look into a tool like Cloudflare for more protection.
    0
  • adeyjones
    Thanks for the reply as always Rex. Unfortunately Cloudflare isn't an option for me. Re mod_evasive, turns out I mustn't have restarted apache, I thought this was done when saving changes in EasyApache but obviously not, however with those settings it started banning genuine people so I disabled it. Have since been playing with CT_Limit in CSF, and again I know you can't comment much about that as it's not cPanel software, but I had CT_Limit set at 150 connections, and when the attack occurred (around 6 hours ago) which usually lasts around 60 minutes it took 27 minutes for the IP to get blocked. So I then lowered CT_Limit to 100 connections and the attack re-occurred around an hour ago, this time it took about 31 minutes which is odd as I expected the time to be shorter, not longer. I've read recommendations not to have CT_Limit lower than 100 (although minimum setting is 10) but i'm tempted to lower to 50 and see what happens on the next attack.
    0

Please sign in to leave a comment.