2015-11-06 13:20:06 +00:00
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A FJ-vnet0 \
|
|
|
|
-p icmp \
|
|
|
|
-m connlimit \
|
|
|
|
--connlimit-above 1 \
|
|
|
|
-j DROP
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A HJ-vnet0 \
|
|
|
|
-p icmp \
|
|
|
|
-m connlimit \
|
|
|
|
--connlimit-above 1 \
|
|
|
|
-j DROP
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A FJ-vnet0 \
|
|
|
|
-p tcp \
|
|
|
|
-m connlimit \
|
|
|
|
--connlimit-above 2 \
|
|
|
|
-j DROP
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A HJ-vnet0 \
|
|
|
|
-p tcp \
|
|
|
|
-m connlimit \
|
|
|
|
--connlimit-above 2 \
|
|
|
|
-j DROP
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A FJ-vnet0 \
|
|
|
|
-p all \
|
2022-02-25 16:24:21 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctstate NEW,ESTABLISHED \
|
2022-02-25 16:28:32 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctdir Original \
|
2015-11-06 13:20:06 +00:00
|
|
|
-j RETURN
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A FP-vnet0 \
|
|
|
|
-p all \
|
2022-02-25 16:24:21 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctstate ESTABLISHED \
|
2022-02-25 16:28:32 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctdir Reply \
|
2015-11-06 13:20:06 +00:00
|
|
|
-j ACCEPT
|
|
|
|
iptables \
|
2020-11-17 00:20:53 +00:00
|
|
|
-w \
|
2015-11-06 13:20:06 +00:00
|
|
|
-A HJ-vnet0 \
|
|
|
|
-p all \
|
2022-02-25 16:24:21 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctstate NEW,ESTABLISHED \
|
2022-02-25 16:28:32 +00:00
|
|
|
-m conntrack \
|
|
|
|
--ctdir Original \
|
2015-11-06 13:20:06 +00:00
|
|
|
-j RETURN
|