From owner-freebsd-questions Mon Jun 17 10: 9:59 2002 Delivered-To: freebsd-questions@freebsd.org Received: from smtp.a1poweruser.com (oh-chardon6a-62.clvhoh.adelphia.net [68.65.175.62]) by hub.freebsd.org (Postfix) with ESMTP id 8F65437B417 for ; Mon, 17 Jun 2002 10:09:53 -0700 (PDT) Received: from barbish (unknown [10.0.10.6]) by smtp.a1poweruser.com (Postfix) with SMTP id 26AF110F; Mon, 17 Jun 2002 13:12:52 -0400 (EDT) Reply-To: From: "Joe & Fhe Barbish" To: "Paulius Bulotas" Cc: "FBSDQ" Subject: RE: limit number of connections per client ip address Date: Mon, 17 Jun 2002 13:09:52 -0400 Message-ID: MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit X-Priority: 3 (Normal) X-MSMail-Priority: Normal X-Mailer: Microsoft Outlook IMO, Build 9.0.2416 (9.0.2911.0) X-MimeOLE: Produced By Microsoft MimeOLE V6.00.2600.0000 In-Reply-To: <20020617100726.GB54160@kaktusas.org> Importance: Normal Sender: owner-freebsd-questions@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.ORG The ipfw limit {src-addr | src-port | dst-addr | dst-port} N is not intended for limiting the number of connections per client ip address. It's intended to limit the number of identical packets per ipfw rule to fort dos flood attacks. -----Original Message----- From: owner-freebsd-questions@FreeBSD.ORG [mailto:owner-freebsd-questions@FreeBSD.ORG]On Behalf Of Paulius Bulotas Sent: Monday, June 17, 2002 6:07 AM To: freebsd questions Subject: Re: limit number of connections per client ip address On 02 06 14, Nielsen wrote: > As far as I know this is not possible in freebsd with either of the > firewalls supplied. Dummynet is for limiting traffic rate, simulating From ipfw man page: limit {src-addr | src-port | dst-addr | dst-port} N The firewall will only allow N connections with the same set of parameters as specified in the rule. One or more of source and destination addresses and ports can be specified. Regards, Paulius To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-questions" in the body of the message