Maximum packet size
Hi. I want to limit maximum packet size transferred per second to 10kb or limit any packet size to 10kb max. can i do this with iptables?
thanks =) |
aren't packet sizes over TCP/IP max 1500 bytes?
|
ooops i didn't knew that... then i want to limit the upload to 10kb/s per second per ip =(
|
use -limit
Yes, that's what the -limit option is all about. But it's limiting frames per second, not bytes per second.
10K bytes / 1500 byte MTU = 6.66 frames per second. So you might add something like "-limit 6 -limit-burst 12" to your iptables rule to ensure you never go over 10K bytes per second. If you make the rule too general (all protocols, all ports), protocols that use smaller frames (eg. IM) will get severely restricted though. YMMV. Good Luck! |
i am stranger to iptables
i want to drop tcp packets coming to 27015 by the -limit 6 -limit-burst 12, can you write the full code :( thanks =) |
it's kind of urgent, can anyone help?
|
Quote:
Code:
iptables -I INPUT -p TCP -i eth0 --dport 27015 \ |
this code drops all the tcp connection on 27015 :(
|
Quote:
Code:
iptables -A INPUT -p TCP -i eth0 --dport 27015 \ |
BTW, I should mention that after reading the OP I think the connbytes match module might be better suited for this than the limit module. It's just a thought.
Code:
connbytes |
yeah i was going to say this, the limit wasn't the rule that i'm looking for but i think connbytes is the thing i am looking for, i'm going to search this, thanks for your help =) you're the best
|
i've searched but i couldn't find.. any help :(
i am also using configserver firewall, i really must do this.. |
Quote:
|
when i have no rules for port 27015 tcp on iptables, it does not allow to access, i think this is normal. but when i try to use connbytes, it does not help at all it does nothing :(
|
Can you post the exact rule you are using? Also, post the output of:
Code:
iptables -nvL |
Code:
[root@denge ~]# iptables -nvL | grep 27015 Code:
iptables -A INPUT -p TCP -i eth0 --dport 27015 \ |
All times are GMT -5. The time now is 05:33 AM. |