forked from freifunk-franken/firmware
Increase SSH Connection Limit
Signed-off-by: Christian Dresel <fff@chrisi01.de> Reviewed-by: Jan Kraus <mayosemmel@gmail.com> Reviewed-by: Tim Niemeyer <tim@tn-x.org>
This commit is contained in:
parent
58c44b574a
commit
bee682345a
|
@ -1,7 +1,7 @@
|
|||
include $(TOPDIR)/rules.mk
|
||||
|
||||
PKG_NAME:=fff-firewall
|
||||
PKG_VERSION:=1
|
||||
PKG_VERSION:=2
|
||||
PKG_RELEASE:=1
|
||||
|
||||
PKG_BUILD_DIR:=$(BUILD_DIR)/fff-firewall
|
||||
|
|
|
@ -2,6 +2,6 @@
|
|||
iptables -A INPUT -i $IF_WAN -m conntrack --ctstate RELATED,ESTABLISHED -j ACCEPT
|
||||
iptables -A INPUT -i $IF_WAN -j REJECT
|
||||
|
||||
# Limit ssh to 3 new connections per 60 seconds
|
||||
# Limit ssh to 6 new connections per 60 seconds
|
||||
/usr/sbin/ip6tables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --set --name dropbear
|
||||
/usr/sbin/ip6tables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 3 --rttl --name dropbear -j DROP
|
||||
/usr/sbin/ip6tables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 6 --rttl --name dropbear -j DROP
|
||||
|
|
Loading…
Reference in New Issue