# Limit to 50 concurrent connections on port 80/443 per IP
-A ufw-before-input -p tcp --syn --dport 80 -m connlimit --connlimit-above 50 -j DROP
-A ufw-before-input -p tcp --syn --dport 443 -m connlimit --connlimit-above 50 -j DROP
# Limit to 100 connections on port 80/443 per 2 seconds per IP
-A ufw-before-input -p tcp --dport 80 -i eth0 -m state --state NEW -m recent --set
-A ufw-before-input -p tcp --dport 80 -i eth0 -m state --state NEW -m recent --update --seconds 2 --hitcount 100 -j DROP
-A ufw-before-input -p tcp --dport 443 -i eth0 -m state --state NEW -m recent --set
-A ufw-before-input -p tcp --dport 443 -i eth0 -m state --state NEW -m recent --update --seconds 2 --hitcount 100 -j DROP
鸡腿,收藏,吃灰,BD
@Lian #20 也是 真要搞你 也防不住
@欧巴 #22
配一下防火墙什么的应该会好点,ufw,fail2ban什么的
Nginx或者Caddy可以配rate limit和waf
开源防火墙推荐Crowdsec
咱站天天被攻击都没事 rt.http3.lol
不错 支持