On Monday 2010-04-12 08:24, ratheesh k wrote: >On Sat, Apr 10, 2010 at 11:12 PM, Jan Engelhardt <jengelh@xxxxxxxxxx> wrote: >> On Saturday 2010-04-10 19:20, ratheesh k wrote: >> >>>> xt_recent works by comparing the difference between an entry's >>>> timestamps and the current time with the chosen --seconds parameter. >>> >>>If an ip is black listed , when it will get removed >> >> It will not get removed. If you want any action, such as blacklisting, >> to stop after a given time, you use --seconds as I just told. > >if number of ip balcklisted ip is more than ip_list_tot , old >entries will be replaced by new ip addresses ? . { once list if full , >what will happen for new black listing } As I see it yes. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html