Re: nftables: first rate limit on IP, then filter on port

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



Hi Alex,

On Fri, Apr 06, 2018 at 04:11:09PM +0200, Alexander Dahl wrote:
> Hello Florian,
>
> Am Freitag, 6. April 2018, 13:28:59 CEST schrieb Florian Westphal:
[...]
> However I did not understand this "over" keyword. The examples on rate
> limiting in the wiki [1] all don't use it and also use accept instead of drop,
> there's not a single example with drop. Maybe the documentation on this should
> be improved?
[...]

Thanks for that:  I too missed the "over" + "drop" combination as a possibility.
It's kind-of intuitively what you want from limit I think, so I updated the
wiki.

However you should be aware that the wiki is not a definitive document: the
command synopsis in *man nft* always did include the "over" keyword.

Cheers ... Duncan.
--
To unsubscribe from this list: send the line "unsubscribe netfilter" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at  http://vger.kernel.org/majordomo-info.html



[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux