Hello Netfilter Community, first message, I would be grateful for any guidance, thanks in advance What I have already, watches for new ipv4_addr that are not on a white/blacklist'set' and adds them to an evaluation set. however I would also like monitor the evaluation set and automatically add to the blacklist any address that for example attempts more than 25 connections on port 22 per hour. probably this is has been explained alas I have yet to find this issue described elsewhere. Best regards -- To unsubscribe from this list: send the line "unsubscribe netfilter" in the body of a message to majordomo@xxxxxxxxxxxxxxx More majordomo info at http://vger.kernel.org/majordomo-info.html