On Sun, 2007-06-03 at 13:12 +0200, Jan Engelhardt wrote:
> Adds the connlimit match that has been in POM-NG for a long time.
>
> * works with 2.6.22, xtables'ified and all that
>
> * will request nf_conntrack_ipv4 upon load
> (otherwise it hotdrops every packet - a glitch that goes back
> to at least 2.6.20.2)
Excellent! This has been at the back of my mind for a while.
Is there any chance of getting UDP flows added as well as TCP
connections? I use connlimit for detecting p2p software, but some p2p
software now uses UDP instead.
Thanks,
Andy Beverley
|