Re: max-src-conn-rate rule question

Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]
From: david l goodrich
Date: Tuesday, October 23, 2007 - 5:30 pm

On Tue, Oct 23, 2007 at 02:55:41PM -0700, Rob wrote:

I don't have an = sign in my rule, either, i have it in pf.conf as:

pass in log proto tcp from any to any port ssh \
        keep state (max-src-conn-rate 3/30, \
                        overload <sshd_attackers> flush global)

but when i look at my rules with pfctl -sr it shows the =.


I want to pass ssh traffic by default, so a block rule won't be
terribly helpful.


Mine's pretty similar, if a bit more verbose.  And I don't use
max-src-conn or queueing.
  --david


Previous message: [thread] [date] [author]
Next message: [thread] [date] [author]

Messages in current thread:
max-src-conn-rate rule question, david l goodrich, (Sun Oct 21, 12:22 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 1:58 pm)
Re: max-src-conn-rate rule question, Calomel, (Tue Oct 23, 2:46 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 2:55 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 5:30 pm)
Re: max-src-conn-rate rule question, Rob, (Tue Oct 23, 5:59 pm)
Re: max-src-conn-rate rule question, Vijay Sankar, (Tue Oct 23, 7:36 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:02 pm)
Re: max-src-conn-rate rule question, david l goodrich, (Tue Oct 23, 9:23 pm)
Re: max-src-conn-rate rule question, Henning Brauer, (Wed Oct 24, 1:12 am)
Re: max-src-conn-rate rule question, Rob, (Wed Oct 24, 5:26 am)
Re: max-src-conn-rate rule question, Calomel, (Wed Oct 24, 8:40 am)