All of lore.kernel.org
 help / color / mirror / Atom feed
From: "Kamil Jońca" <kjonca@op.pl>
To: netfilter@vger.kernel.org
Subject: Re: how to use meters?
Date: Mon, 19 Sep 2022 12:00:44 +0200	[thread overview]
Message-ID: <87czbrn0oj.fsf@alfa.kjonca> (raw)
In-Reply-To: <Yygss6Pkwuwgmy4o@salvia> (Pablo Neira Ayuso's message of "Mon, 19 Sep 2022 10:47:47 +0200")

Pablo Neira Ayuso <pablo@netfilter.org> writes:

> On Sun, Sep 18, 2022 at 12:49:34PM +0200, Kamil Joñca wrote:
> [...]
>> For example:
>> https://wiki.archlinux.org/title/Nftables#Dynamic_blackhole
>> --8<---------------cut here---------------start------------->8---
>>  ct state new tcp dport 443 \
>>                 meter flood size 128000 { ip saddr timeout 10s limit rate over 10/second } \
>>                 add @blackhole { ip saddr timeout 1m }
>> --8<---------------cut here---------------end--------------->8---
>> 
>> I understand " add @blackhole { ip saddr timeout 1m }" - adds address to
>> set for 1 min.
>> but what is
>> "meter flood size 128000 { ip saddr timeout 10s limit rate over 10/second }"
>> 
>> (I can guess but I cannot see proper doc of this)
>> Any hint?
>
> I'd suggest you use a set declaration for this, instead of the meter syntax.
>
> This example shows how to ratelimit new connections to 10 per second:
>

[... snip ...]
Thank you. After some digging and reading manual (especially "SET
STATEMET" ) i wrote similar thing (two tables flood +blaclist, etc)
So thanks for confirmation. :)

The only thing is
"    set flood {
        type ipv4_addr
        flags dynamic
        timeout 1m
        limit rate over 10/second
        size 65536
    }
"

I did not found "limit" statement in set definition in manual.
Am I overlooked something?

KJ

-- 
http://wolnelektury.pl/wesprzyj/teraz/

      reply	other threads:[~2022-09-19 10:00 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-09-18 10:49 how to use meters? Kamil Jońca
2022-09-19  8:47 ` Pablo Neira Ayuso
2022-09-19 10:00   ` Kamil Jońca [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=87czbrn0oj.fsf@alfa.kjonca \
    --to=kjonca@op.pl \
    --cc=netfilter@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.