Thanks! However when i was reading xt_hashlimit.c , it notice that it is actually doing credit = cfg.avg * cfg.burst , how would that work? Also, I just want to confirm that this rule is packet by packet matching, right? i have all traffic under NOTRACK. Thanks. -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html