nftables: Bump burst to 10 packets.

This commit is contained in:
Viyurz 2024-02-25 19:28:21 +01:00
parent bf6b958ed7
commit d211d596c4
Signed by: Viyurz
SSH key fingerprint: SHA256:IskOHTmhHSJIvAt04N6aaxd5SZCVWW1Guf9tEcxIMj8

View file

@ -38,10 +38,10 @@ table inet filter {
# Prevent DDoS # Prevent DDoS
# Rate limiting # Rate limiting
meta nfproto ipv4 meter ratelimit4 \ meta nfproto ipv4 meter ratelimit4 \
{ ip saddr limit rate over 50/second burst 5 packets } \ { ip saddr limit rate over 50/second burst 10 packets } \
add @blackhole_ipv4 { ip saddr } add @blackhole_ipv4 { ip saddr }
meta nfproto ipv6 meter ratelimit6 \ meta nfproto ipv6 meter ratelimit6 \
{ ip6 saddr limit rate over 50/second burst 5 packets } \ { ip6 saddr limit rate over 50/second burst 10 packets } \
add @blackhole_ipv6 { ip6 saddr } add @blackhole_ipv6 { ip6 saddr }
# Max concurrent connections # Max concurrent connections
meta nfproto ipv4 meter connlimit4 \ meta nfproto ipv4 meter connlimit4 \