From: "Gilad Benjamini" <gilad.benjamini@gmail.com>
To: netfilter@vger.kernel.org
Subject: RE: iptables - how to create a rule that expires automatically
Date: Thu, 19 Feb 2009 10:18:22 -0800 [thread overview]
Message-ID: <499da285.18068e0a.2a5f.ffffc031@mx.google.com> (raw)
In-Reply-To: <84965006-A4F7-41DD-8C6F-ED62AA82B2F9@dancing.org>
One thing to note is that you actually delete the exact same rule you added.
There is no built-in method to do that.
I can think of a few ideas how to verify that (with high probability, not
100%) but it really depends on the actual requirements.
> -----Original Message-----
> From: netfilter-owner@vger.kernel.org [mailto:netfilter-
> owner@vger.kernel.org] On Behalf Of Peter Renzland
> Sent: Thursday, February 19, 2009 9:57 AM
> To: Colin Davis
> Cc: netfilter@vger.kernel.org
> Subject: Re: iptables - how to create a rule that expires automatically
>
> I would write a simple script "ipoff NN" which takes the same
> arguments as iptables (after NN), converts -I and -A to -D, etc, and
> sleeps NN minutes before doing the cancel.
>
> Then, after running the command that sets up the rule, I would just
> arrow up and change iptables to ipoff NN.
> That would be *very usable*, IMHO.
>
> (I most definitely would not use cron or at, since those tools do not
> naturally match the problem at all.)
>
>
> Peter
>
>
> On 09 Feb 19, at 12:42 , Colin Davis wrote:
>
> >
> > Thanks Ivan, I was hoping to be able to do this directly using a rule
> > without writing a script / using cron but looks like that's what I'm
> > going
> > to have to do.
> >
> > Colin.
> >
> >
> > Ivan Petrushev wrote:
> >> I'm not sure if that can be done with the netfilter itself.
> >> You could always get a script into crontab to check if the rule is
> >> matched (iptables ... -L -n -v will show you number of packets
> >> matched
> >> by the rule) and set up some sort of a timer.
> >>
> >> Ivan
> >>
> >> On Thu, Feb 19, 2009 at 7:10 PM, Colin Davis <col@colsmemory.co.uk>
> >> wrote:
> >>
> >>> Hi,
> >>>
> >>> Not sure if this is possible. I wish to create a rule that once
> >>> created will
> >>> automatically expire (and be removed) after say 10 minutes.
> >>>
> >>> Please
> >>>
> >>> Many thanks,
> >>> Colin.
> >>> --
> >>> To unsubscribe from this list: send the line "unsubscribe
> >>> netfilter" in
> >>> the body of a message to majordomo@vger.kernel.org
> >>> More majordomo info at http://vger.kernel.org/majordomo-info.html
> >>>
> >>>
> >
> > --
> > To unsubscribe from this list: send the line "unsubscribe netfilter"
> > in
> > the body of a message to majordomo@vger.kernel.org
> > More majordomo info at http://vger.kernel.org/majordomo-info.html
> >
>
> --
> To unsubscribe from this list: send the line "unsubscribe netfilter" in
> the body of a message to majordomo@vger.kernel.org
> More majordomo info at http://vger.kernel.org/majordomo-info.html
next prev parent reply other threads:[~2009-02-19 18:18 UTC|newest]
Thread overview: 13+ messages / expand[flat|nested] mbox.gz Atom feed top
2009-02-19 17:10 iptables - how to create a rule that expires automatically Colin Davis
2009-02-19 17:32 ` Simon Gray
2009-02-19 17:36 ` Ivan Petrushev
2009-02-19 17:42 ` Colin Davis
2009-02-19 17:56 ` Peter Renzland
2009-02-19 18:14 ` Colin Davis
2009-02-19 18:15 ` Peter Renzland
2009-02-19 18:17 ` Ivan Petrushev
2009-02-19 18:18 ` Gilad Benjamini [this message]
2009-02-19 17:48 ` Gilad Benjamini
2009-02-19 18:36 ` G.W. Haywood
2009-02-20 9:01 ` Mart Frauenlob
2009-02-20 9:16 ` Michael Schwartzkopff
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=499da285.18068e0a.2a5f.ffffc031@mx.google.com \
--to=gilad.benjamini@gmail.com \
--cc=netfilter@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox