logoalt Hacker News

VladVladikofftoday at 1:24 AM1 replyview on HN

Have you noticed significant slowdown and CPU usage from failban with that many banned IPs? I saw it becoming a huge resource hog with far less IPs than that.


Replies

PaulDavisThe1sttoday at 2:24 PM

Yeah, when we hit about 80-100k banned hosts, iptables causes issues.

There are versions of iptables available that apparently can scale to 1M+ addresses, but our approach is just to unban all at that point, and then let things accumulate again.

Since we because responding with 404 to all commit URLs, the rate of banned address accumulation has slowed down quite a bit.