No more connection limits

Might revert if this gets abused too much, but bypassing it with open proxies is easy, and most skiddies use services (that use proxies) for their spambotting anyway. In my opinion, this causes more problems than it prevents.
This commit is contained in:
Chipmunk 2023-01-17 16:31:44 -05:00
parent e11c1ad80b
commit 32479825d4

View file

@ -1,11 +1,11 @@
# IPv4
iptables -t nat -A INPUT -p tcp --dport 25565 -j SNAT --to-source 192.168.1.0-192.168.100.100
iptables -t nat -A INPUT -p udp --dport 19132 -j SNAT --to-source 192.168.1.0-192.168.100.100
iptables -A INPUT -p tcp --syn --dport 25565 -m connlimit --connlimit-above 5 --connlimit-mask 32 -j REJECT --reject-with tcp-reset
tcp-reset
iptables-save > /etc/iptables/rules.v4
# IPv6
ip6tables -t nat -A INPUT -p tcp --dport 25565 -j SNAT --to-source 2001:db8::1-2001:db8::6464
ip6tables -t nat -A INPUT -p udp --dport 19132 -j SNAT --to-source 2001:db8::1-2001:db8::6464
ip6tables -A INPUT -p tcp --syn --dport 25565 -m connlimit --connlimit-above 5 --connlimit-mask 64 -j REJECT --reject-with tcp-reset
tcp-reset
ip6tables-save > /etc/iptables/rules.v6