Re: ipset swap to nftables set

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



On Friday, September 29th, 2023 at 06:44, marek <cervajs64@xxxxxxxxx> wrote:
> - nft flush set ip filter blackhole
> 
> - nft add element ip filter blackhole { X } (bash for loop)

Hi Marek,

Do that last step atomically and it should be plenty fast.

nft flush set ip filter blackhole
nft add element ip filter blackhole {\
    1.0.0.1, \
    1.0.0.2, \
    1.0.0.3, \
    1.1.1.1, \
    1.1.1.2, \
    1.1.1.3, \
    1.193.146.35, \
...
    99.99.99.99, \
}

Eric




[Index of Archives]     [Linux Netfilter Development]     [Linux Kernel Networking Development]     [Netem]     [Berkeley Packet Filter]     [Linux Kernel Development]     [Advanced Routing & Traffice Control]     [Bugtraq]

  Powered by Linux