From cb136ee5aebb23aebc1c47a30a9ff55bbbf2aa4c Mon Sep 17 00:00:00 2001 From: Priit Tark Date: Tue, 26 May 2015 08:04:14 +0300 Subject: [PATCH] Use rcheck instead update --- doc/debian_build_doc.md | 12 ++++++------ 1 file changed, 6 insertions(+), 6 deletions(-) diff --git a/doc/debian_build_doc.md b/doc/debian_build_doc.md index e2e604d92..c2d40f56c 100644 --- a/doc/debian_build_doc.md +++ b/doc/debian_build_doc.md @@ -64,10 +64,10 @@ IPT=/sbin/iptables SECONDS=60 # Max connections per IP BLOCKCOUNT=100 -# default action can be DROP or REJECT +# default action can be DROP or REJECT or something else. DACTION="REJECT" $IPT -A INPUT -p tcp --dport 80 -i eth0 -m state --state NEW -m recent --set -$IPT -A INPUT -p tcp --dport 80 -i eth0 -m state --state NEW -m recent --update --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} +$IPT -A INPUT -p tcp --dport 80 -i eth0 -m state --state NEW -m recent --rcheck --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} ```` #### EPP @@ -80,10 +80,10 @@ IPT=/sbin/iptables SECONDS=60 # Max connections per IP BLOCKCOUNT=100 -# default action can be DROP or REJECT +# default action can be DROP or REJECT or something else. DACTION="REJECT" $IPT -A INPUT -p tcp --dport 700 -i eth0 -m state --state NEW -m recent --set -$IPT -A INPUT -p tcp --dport 700 -i eth0 -m state --state NEW -m recent --update --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} +$IPT -A INPUT -p tcp --dport 700 -i eth0 -m state --state NEW -m recent --rcheck --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} ```` #### Whois @@ -96,9 +96,9 @@ IPT=/sbin/iptables SECONDS=60 # Max connections per IP BLOCKCOUNT=100 -# default action can be DROP or REJECT +# default action can be DROP or REJECT or something else. DACTION="REJECT" $IPT -A INPUT -p tcp --dport 43 -i eth0 -m state --state NEW -m recent --set -$IPT -A INPUT -p tcp --dport 43 -i eth0 -m state --state NEW -m recent --update --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} +$IPT -A INPUT -p tcp --dport 43 -i eth0 -m state --state NEW -m recent --rcheck --seconds ${SECONDS} --hitcount ${BLOCKCOUNT} -j ${DACTION} ````