Switch to reject and lower burst

This commit is contained in:
Alex D. 2022-04-03 20:24:11 +00:00
parent f958cb11ec
commit 62169a0990
Signed by: caskd
GPG Key ID: F92BA85F61F4C173
2 changed files with 5 additions and 5 deletions

View File

@ -3,7 +3,7 @@
. ../APKBUILD-config.template
pkgver=2022.04.03.02
pkgver=2022.04.03.04
pkgrel=0
options="!check" # check requires root?

View File

@ -2,8 +2,8 @@
#iifname "eth0" ct state new meter limit6 { ip6 saddr ct count over 10 } counter reject;
# Ban if connection attempts are still made over the limit
iifname "eth0" ct state new meter ban4 { ip saddr timeout 10m limit rate over 1/second burst 30 packets } update @blackhole4 { ip saddr timeout 10m } counter drop;
iifname "eth0" ct state new meter ban6 { ip6 saddr timeout 10m limit rate over 1/second burst 30 packets } update @blackhole6 { ip6 saddr timeout 10m } counter drop;
iifname "eth0" ct state new meter ban4 { ip saddr timeout 10m limit rate over 1/second burst 20 packets } update @blackhole4 { ip saddr timeout 10m } counter reject;
iifname "eth0" ct state new meter ban6 { ip6 saddr timeout 10m limit rate over 1/second burst 20 packets } update @blackhole6 { ip6 saddr timeout 10m } counter reject;
iifname "eth0" ct state new meter drop4 { ip saddr timeout 10m limit rate over 1/second } counter drop;
iifname "eth0" ct state new meter drop6 { ip6 saddr timeout 10m limit rate over 1/second } counter drop;
iifname "eth0" ct state new meter drop4 { ip saddr timeout 10m limit rate over 1/second } counter reject;
iifname "eth0" ct state new meter drop6 { ip6 saddr timeout 10m limit rate over 1/second } counter reject;