I would suggest the following method:- 1. Go through the network activity logs, and estimate the average no of packets per unit time that you consider as normal to your packet. 2. Then think of a tolerance margin. 3. Write appropriate rules for limting the rate of packets. I would recommend genarating a cron job that estimates the average number of packets per unit time after every day, and update the rule in filter table. Again optimal estimation is not a trivial job as it depends on several factors. On Mon, 27 Dec 2004 17:40:26 -0200, Bruno Wallace <bruno.wallace@xxxxxxxxx> wrote: > hello everybody, > what rule is implemented to udp packet storm? > -- > thanks, > Bruno Wallace > > -- cheers Ashish -- cheers Ashish