Hi, >Looking at the --limit related options, it seems that all of the >options are about limiting rate, not duration of a connection. Look at "recent" match and "CONNMARK/connmark" target/match. I think it could do what you want. best regards, Marek Kierdelewicz -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html