Fri Sep 02, 2005 9:07 am
im using someting like this :
add chain=forward in-interface="internal_bridge" protocol=tcp dst-port=0-80 \
tcp-flags=syn,!fin,!rst,!psh,!ack,!urg,!ece,!cwr connection-limit=15,32 \
action=drop comment="Connlimit" disabled=no
add chain=forward in-interface="internal_bridge" protocol=tcp dst-port=81-442 \
tcp-flags=syn,!fin,!rst,!psh,!ack,!urg,!ece,!cwr connection-limit=15,32 \
action=drop comment="" disabled=no
add chain=forward in-interface="internal_bridge" protocol=tcp dst-port=443 \
tcp-flags=syn,!fin,!rst,!psh,!ack,!urg,!ece,!cwr connection-limit=50,32 \
action=drop comment="" disabled=no
add chain=forward in-interface="internal_bridge" src-address=!192.168.0.98 \
protocol=tcp dst-port=444-65535 \
tcp-flags=syn,!fin,!rst,!psh,!ack,!urg,!ece,!cwr connection-limit=5,32 \
action=drop comment="limit444" disabled=no
additionalny scheduler changing rule "limit444" from 5 to 400 connection per user from 0.30 till 7.30.