Re: ip_conntrack_max vs ip_conntrack

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Thu, 2004-09-30 at 18:48, Jiann-Ming Su wrote:
> 
> There's some good info on what I was looking for at the end of this section:
> 
> http://www.iptables.org/documentation/HOWTO//packet-filtering-HOWTO-7.html#ss7.3
> 
> Does the limit option work on a per connection basis?  Or, does one
> attacker's syn flood cause everybody to be limited as well?

the limit match works per-rule.  however you define what matches the
rule is what will be limited.

-j

-- 
Jason Opperisano <opie@xxxxxxxxxxx>



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux