Cc'ing Duncan. On Thu, Dec 28, 2017 at 12:58:33PM +0530, Harsha Sharma wrote: > Do not print timeout and burst in case default values are used. > For e.g. > iptables-translate -A INPUT -m tcp -p tcp --dport 80 -m hashlimit > --hashlimit-above 200/sec --hashlimit-mode srcip,dstport > --hashlimit-name http1 -j DROP > > nft add rule ip filter INPUT tcp dport 80 flow table http1 { tcp dport . > ip saddr limit rate over 200/second } counter drop This is what I was asking for. Applied, thanks Harsha. @Duncan: I think you can update the wiki again after this, given that now those values should not be printed. -- To unsubscribe from this list: send the line "unsubscribe netfilter-devel" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html