Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #270751

Re: timeout for iptables

From Jeff Peng <jeff@simplemail.co.in>
Newsgroups linux.debian.user
Subject Re: timeout for iptables
Date 2024-07-03 05:40 +0200
Message-ID <IVZ0B-7jal-3@gated-at.bofh.it> (permalink)
References <IVKbf-79in-1@gated-at.bofh.it> <IVSiu-7eDa-9@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


Got the idea (nft) and thanks for all help.

On 2024-07-03 04:22, Tim Woodall wrote:
> On Tue, 2 Jul 2024, Jeff Peng wrote:
> 
>> Hello gurus,
>> 
>> Is there a tool for maintaining the timeout for iptables rules?
>> 
>> for example, one IP would be blocked by my iptables for 24 hours, and 
>> another IP should be blocked for one week.
>> 
> 
> Off the top of my head I can't think exactly how to do it but I think
> you can use -m hashlimit and use the --hastlimit-htable-expire to time
> things out.
> 
> But this will depend on exactly what you're doing. If you're adding
> something to the hashtable that keeps happening then it might not
> expire the way you want.

Back to linux.debian.user | Previous | Next — Previous in thread | Find similar | Unroll thread


Thread

timeout for iptables Jeff Peng <jeff@simplemail.co.in> - 2024-07-02 13:50 +0200
  Re: timeout for iptables Dan Ritter <dsr@randomstring.org> - 2024-07-02 14:50 +0200
    Re: timeout for iptables Max Nikulin <manikulin@gmail.com> - 2024-07-02 16:10 +0200
      Re: timeout for iptables Dan Ritter <dsr@randomstring.org> - 2024-07-02 16:30 +0200
  Re: timeout for iptables Tim Woodall <debianuser@woodall.me.uk> - 2024-07-02 22:30 +0200
    Re: timeout for iptables Jeff Peng <jeff@simplemail.co.in> - 2024-07-03 05:40 +0200

csiph-web