netfilter.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* Accept clients that were seen at least twice only
@ 2015-08-26 12:21 Jeff
  2015-08-26 12:46 ` André Paulsberg-Csibi
  0 siblings, 1 reply; 3+ messages in thread
From: Jeff @ 2015-08-26 12:21 UTC (permalink / raw)
  To: netfilter

Hello everybody,

I am looking for a way to accept traffic from clients only if they were 
seen at least twice. This shall be part of a firewall concept which 
protects the target from random floods where source IPs are usually only 
seen once since they are random.
I cannot use the --state ESTABLISHED here because this requires a 
complete handshake (for TCP). I'm okay with the first packet not 
matching this rule as long as the 2nd one does. I'm looking forward to 
reading your ideas!


Best,
Jeff

^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2015-08-26 12:51 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2015-08-26 12:21 Accept clients that were seen at least twice only Jeff
2015-08-26 12:46 ` André Paulsberg-Csibi
2015-08-26 12:51   ` Jeff

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).