Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #270748

Re: timeout for iptables

From Tim Woodall <debianuser@woodall.me.uk>
Newsgroups linux.debian.user
Subject Re: timeout for iptables
Date 2024-07-02 22:30 +0200
Message-ID <IVSiu-7eDa-9@gated-at.bofh.it> (permalink)
References <IVKbf-79in-1@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


On Tue, 2 Jul 2024, Jeff Peng wrote:

> Hello gurus,
>
> Is there a tool for maintaining the timeout for iptables rules?
>
> for example, one IP would be blocked by my iptables for 24 hours, and another 
> IP should be blocked for one week.
>

Off the top of my head I can't think exactly how to do it but I think
you can use -m hashlimit and use the --hastlimit-htable-expire to time
things out.

But this will depend on exactly what you're doing. If you're adding
something to the hashtable that keeps happening then it might not
expire the way you want.

Back to linux.debian.user | Previous | Next — Previous in thread | Next in thread | Find similar | Unroll thread


Thread

timeout for iptables Jeff Peng <jeff@simplemail.co.in> - 2024-07-02 13:50 +0200
  Re: timeout for iptables Dan Ritter <dsr@randomstring.org> - 2024-07-02 14:50 +0200
    Re: timeout for iptables Max Nikulin <manikulin@gmail.com> - 2024-07-02 16:10 +0200
      Re: timeout for iptables Dan Ritter <dsr@randomstring.org> - 2024-07-02 16:30 +0200
  Re: timeout for iptables Tim Woodall <debianuser@woodall.me.uk> - 2024-07-02 22:30 +0200
    Re: timeout for iptables Jeff Peng <jeff@simplemail.co.in> - 2024-07-03 05:40 +0200

csiph-web