nftables: Bump burst to 10 packets.
This commit is contained in:
parent
bf6b958ed7
commit
d211d596c4
1 changed files with 2 additions and 2 deletions
|
@ -38,10 +38,10 @@ table inet filter {
|
|||
# Prevent DDoS
|
||||
# Rate limiting
|
||||
meta nfproto ipv4 meter ratelimit4 \
|
||||
{ ip saddr limit rate over 50/second burst 5 packets } \
|
||||
{ ip saddr limit rate over 50/second burst 10 packets } \
|
||||
add @blackhole_ipv4 { ip saddr }
|
||||
meta nfproto ipv6 meter ratelimit6 \
|
||||
{ ip6 saddr limit rate over 50/second burst 5 packets } \
|
||||
{ ip6 saddr limit rate over 50/second burst 10 packets } \
|
||||
add @blackhole_ipv6 { ip6 saddr }
|
||||
# Max concurrent connections
|
||||
meta nfproto ipv4 meter connlimit4 \
|
||||
|
|
Loading…
Reference in a new issue