No more connection limits
Might revert if this gets abused too much, but bypassing it with open proxies is easy, and most skiddies use services (that use proxies) for their spambotting anyway. In my opinion, this causes more problems than it prevents.
This commit is contained in:
parent
e11c1ad80b
commit
32479825d4
1 changed files with 2 additions and 2 deletions
|
@ -1,11 +1,11 @@
|
|||
# IPv4
|
||||
iptables -t nat -A INPUT -p tcp --dport 25565 -j SNAT --to-source 192.168.1.0-192.168.100.100
|
||||
iptables -t nat -A INPUT -p udp --dport 19132 -j SNAT --to-source 192.168.1.0-192.168.100.100
|
||||
iptables -A INPUT -p tcp --syn --dport 25565 -m connlimit --connlimit-above 5 --connlimit-mask 32 -j REJECT --reject-with tcp-reset
|
||||
tcp-reset
|
||||
iptables-save > /etc/iptables/rules.v4
|
||||
|
||||
# IPv6
|
||||
ip6tables -t nat -A INPUT -p tcp --dport 25565 -j SNAT --to-source 2001:db8::1-2001:db8::6464
|
||||
ip6tables -t nat -A INPUT -p udp --dport 19132 -j SNAT --to-source 2001:db8::1-2001:db8::6464
|
||||
ip6tables -A INPUT -p tcp --syn --dport 25565 -m connlimit --connlimit-above 5 --connlimit-mask 64 -j REJECT --reject-with tcp-reset
|
||||
tcp-reset
|
||||
ip6tables-save > /etc/iptables/rules.v6
|
||||
|
|
Loading…
Reference in a new issue