Advertisement
Guest User

nftables meter

a guest
Sep 16th, 2019
122
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
Perl 3.37 KB | None | 0 0
  1. nft add table filter
  2. nft add chain filter input {type filter hook input priority 0\;}
  3.  
  4. ----------
  5. Attempt 1:
  6. ----------
  7. nft add rule inet filter input ct state new tcp dport 22 meter rate_limit \{ ip saddr limit rate 10/second \} accept
  8.  
  9. Error: Could not process rule: No such file or directory
  10. add rule inet filter input ct state new tcp dport 22 meter rate_limit { ip saddr limit rate 10/second } accept
  11. ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  12.  
  13. ---------
  14. Attept 2:
  15. ---------
  16. nft add rule inet filter input tcp dport 22 ct state new meter \{ ip saddr limit rate 10/second \} accept
  17.  
  18. Error: syntax error, unexpected '{', expecting string
  19. add rule inet filter input tcp dport 22 ct state new meter { ip saddr limit rate 10/second } accept
  20.                                                            ^
  21. ---------
  22. Attempt 3:
  23. ---------
  24. nft add set filter rate_limit { type ipv4_addr\; flags constant, interval \;}
  25. nft add rule inet filter input tcp dport 22 ct state new meter rate_limit \{ ip saddr limit rate 10/second \} accept
  26.  
  27.  
  28. Error: Could not process rule: No such file or directory
  29. add rule inet filter input tcp dport 22 ct state new meter rate_limit { ip saddr limit rate 10/second } accept
  30.                                                                         ^^^^^^^^
  31. Error: Could not process rule: No such file or directory
  32. add rule inet filter input tcp dport 22 ct state new meter rate_limit { ip saddr limit rate 10/second } accept
  33. ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  34.  
  35. ---------
  36. Attempt 4:
  37. ---------
  38. nft list ruleset
  39.  
  40. table ip filter {
  41.     set rate_limit {
  42.         type ipv4_addr
  43.         flags constant,interval
  44.     }
  45.  
  46.     chain input {
  47.         type filter hook input priority 0; policy accept;
  48.     }
  49. }
  50.  
  51.  
  52. nft add rule inet filter input ct state new tcp dport \{22, 2222\} meter rate_limit \{ ip saddr . tcp dport limit rate over 10/minute \} drop
  53.  
  54. Error: Could not process rule: No such file or directory
  55. add rule inet filter input ct state new tcp dport {22, 2222} meter rate_limit { ip saddr . tcp dport limit rate over 10/minute } drop
  56.                                                   ^^^^^^^^^^
  57. Error: Could not process rule: No such file or directory
  58. add rule inet filter input ct state new tcp dport {22, 2222} meter rate_limit { ip saddr . tcp dport limit rate over 10/minute } drop
  59.                                                   ^^^^^^^^^^
  60. Error: Could not process rule: No such file or directory
  61. add rule inet filter input ct state new tcp dport {22, 2222} meter rate_limit { ip saddr . tcp dport limit rate over 10/minute } drop
  62.                                                                                 ^^^^^^^^^^^^^^^^^^^^
  63. Error: Could not process rule: No such file or directory
  64. add rule inet filter input ct state new tcp dport {22, 2222} meter rate_limit { ip saddr . tcp dport limit rate over 10/minute } drop
  65. ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
  66.  
  67. ---------
  68. Attempt 5:
  69. ---------
  70. nft add rule inet filter input tcp dport 22 ct state new meter \{ ip saddr limit rate 10/second \}
  71.  
  72. Error: syntax error, unexpected '{', expecting string
  73. add rule inet filter input tcp dport 22 ct state new meter { ip saddr limit rate 10/second }
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement