Linux Netfilter discussions
 help / color / mirror / Atom feed
From: Colin Davis <col@colsmemory.co.uk>
To: Peter Renzland <peter@dancing.org>
Cc: netfilter@vger.kernel.org
Subject: Re: iptables - how to create a rule that expires automatically
Date: Thu, 19 Feb 2009 18:14:06 +0000	[thread overview]
Message-ID: <499DA16E.8060909@colsmemory.co.uk> (raw)
In-Reply-To: <84965006-A4F7-41DD-8C6F-ED62AA82B2F9@dancing.org>


Thanks Peter, definitely pointed me in a better direction.

Colin.


Peter Renzland wrote:
> I would write a simple script "ipoff NN" which takes the same 
> arguments as iptables (after NN), converts -I and -A to -D, etc, and 
> sleeps NN minutes before doing the cancel.
>
> Then, after running the command that sets up the rule, I would just 
> arrow up and change iptables to ipoff NN.
> That would be *very usable*, IMHO.
>
> (I most definitely would not use cron or at, since those tools do not 
> naturally match the problem at all.)
>
>
> Peter
>
>
> On 09  Feb 19, at 12:42 , Colin Davis wrote:
>
>>
>> Thanks Ivan, I was hoping to be able to do this directly using a rule
>> without writing a script / using cron but looks like that's what I'm 
>> going
>> to have to do.
>>
>> Colin.
>>
>>
>> Ivan Petrushev wrote:
>>> I'm not sure if that can be done with the netfilter itself.
>>> You could always get a script into crontab to check if the rule is
>>> matched (iptables ... -L -n -v will show you number of packets matched
>>> by the rule) and set up some sort of a timer.
>>>
>>> Ivan
>>>
>>> On Thu, Feb 19, 2009 at 7:10 PM, Colin Davis <col@colsmemory.co.uk> 
>>> wrote:
>>>
>>>> Hi,
>>>>
>>>> Not sure if this is possible. I wish to create a rule that once 
>>>> created will
>>>> automatically expire (and be removed) after say 10 minutes.
>>>>
>>>> Please
>>>>
>>>> Many thanks,
>>>> Colin.
>>>> -- 
>>>> To unsubscribe from this list: send the line "unsubscribe 
>>>> netfilter" in
>>>> the body of a message to majordomo@vger.kernel.org
>>>> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>>>>
>>>>
>>
>> -- 
>> To unsubscribe from this list: send the line "unsubscribe netfilter" in
>> the body of a message to majordomo@vger.kernel.org
>> More majordomo info at  http://vger.kernel.org/majordomo-info.html
>>
>


  reply	other threads:[~2009-02-19 18:14 UTC|newest]

Thread overview: 13+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2009-02-19 17:10 iptables - how to create a rule that expires automatically Colin Davis
2009-02-19 17:32 ` Simon Gray
2009-02-19 17:36 ` Ivan Petrushev
2009-02-19 17:42   ` Colin Davis
2009-02-19 17:56     ` Peter Renzland
2009-02-19 18:14       ` Colin Davis [this message]
2009-02-19 18:15       ` Peter Renzland
2009-02-19 18:17       ` Ivan Petrushev
2009-02-19 18:18       ` Gilad Benjamini
2009-02-19 17:48 ` Gilad Benjamini
2009-02-19 18:36 ` G.W. Haywood
2009-02-20  9:01 ` Mart Frauenlob
2009-02-20  9:16   ` Michael Schwartzkopff

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=499DA16E.8060909@colsmemory.co.uk \
    --to=col@colsmemory.co.uk \
    --cc=netfilter@vger.kernel.org \
    --cc=peter@dancing.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox