forked from freifunk-franken/firmware
Fabian Blaese
52e15e072c
This firewall was introduced as a countermeasure for very slow routers directly connected to the internet without any firewall. Our routers have got quite a bit faster since then. Also, a setup like this is highly uncommon, especially for slower routers. Therefore this firewall rule is removed. Fixes: #138 Signed-off-by: Fabian Bläse <fabian@blaese.de> Reviewed-by: Adrian Schmutzler <freifunk@adrianschmutzler.de> Reviewed-by: Robert Langhammer <rlanghammer@web.de> [bump PKG_RELEASE] Signed-off-by: Adrian Schmutzler <freifunk@adrianschmutzler.de>
4 lines
304 B
Plaintext
4 lines
304 B
Plaintext
# Limit ssh to 6 new connections per 60 seconds
|
|
/usr/sbin/ip6tables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --set --name dropbear
|
|
/usr/sbin/ip6tables -A INPUT -p tcp --dport 22 -m conntrack --ctstate NEW -m recent --update --seconds 60 --hitcount 6 --rttl --name dropbear -j DROP
|