Hello, I think Litespeed has already many good security features built in, yet there are a couple of things that I would love to see implemented.
This would be all I need to leave Apache for good.
These features are provided in mod_evasive and mod_cband for Apache, but having them integrated into the webserver would be a different thing, really much better in terms of maintainability and troubleshooting.
1) Ban an IP address after a certain number of requests in a custom time window. For example, ban an IP if it does more than 20 requests in 5 seconds.
2) Ban (or trigger a redirect, or show a custom page) an IP address if it downloads a user definable amount of data in a certain time frame. For example, ban an IP address if it downloads more than 200MB in 24 hours.
Obviously these rules could be improved in many ways: running a shell script when they are triggered or the possibility to define multiple rules of each kind on a vhost basis are just two of them.
Will these features ever appear in Litespeed? Is there an ETA? Even if only for the enterprise version that would be a great think, IMHO.
Regards,
-Mark
This would be all I need to leave Apache for good.
These features are provided in mod_evasive and mod_cband for Apache, but having them integrated into the webserver would be a different thing, really much better in terms of maintainability and troubleshooting.
1) Ban an IP address after a certain number of requests in a custom time window. For example, ban an IP if it does more than 20 requests in 5 seconds.
2) Ban (or trigger a redirect, or show a custom page) an IP address if it downloads a user definable amount of data in a certain time frame. For example, ban an IP address if it downloads more than 200MB in 24 hours.
Obviously these rules could be improved in many ways: running a shell script when they are triggered or the possibility to define multiple rules of each kind on a vhost basis are just two of them.
Will these features ever appear in Litespeed? Is there an ETA? Even if only for the enterprise version that would be a great think, IMHO.
Regards,
-Mark