mirror of
https://github.com/GrapheneOS/infrastructure.git
synced 2024-06-14 00:42:19 +00:00
Compare commits
3 Commits
cb561de104
...
6a325f8798
Author | SHA1 | Date | |
---|---|---|---|
|
6a325f8798 | ||
|
bd6f127acf | ||
|
c412fec336 |
|
@ -45,8 +45,7 @@ table inet filter {
|
|||
fib daddr . iif type != { local, broadcast, multicast } counter drop
|
||||
|
||||
# handle new TCP connections beyond rate limit via synproxy to avoid conntrack table exhaustion
|
||||
tcp dport { 22, 25, 80, 443, 465, 993 } tcp flags syn limit rate 1024/second burst 128 packets accept
|
||||
tcp dport { 22, 25, 80, 443, 465, 993 } tcp flags syn counter notrack accept
|
||||
tcp dport { 22, 25, 80, 443, 465, 993 } tcp flags syn limit rate over 1024/second burst 128 packets counter notrack accept
|
||||
|
||||
meta l4proto { icmp, ipv6-icmp } notrack accept
|
||||
}
|
||||
|
|
Loading…
Reference in New Issue
Block a user