>> -m connlimit > > Not to be a stickler, but does connlimit have a way to control the > total number of combined in AND out bound connections a host has? That does not exist yet AFAICS. You would have to combine hashlimit with connlimit, creating a new kernel module, somehow... --