Re: timeout for iptables

2024-07-02 Thread Jeff Peng
Got the idea (nft) and thanks for all help. On 2024-07-03 04:22, Tim Woodall wrote: On Tue, 2 Jul 2024, Jeff Peng wrote: Hello gurus, Is there a tool for maintaining the timeout for iptables rules? for example, one IP would be blocked by my iptables for 24 hours, and another IP should be

Re: timeout for iptables

2024-07-02 Thread Tim Woodall
On Tue, 2 Jul 2024, Jeff Peng wrote: Hello gurus, Is there a tool for maintaining the timeout for iptables rules? for example, one IP would be blocked by my iptables for 24 hours, and another IP should be blocked for one week. Off the top of my head I can't think exactly how to do it but

Re: timeout for iptables

2024-07-02 Thread Dan Ritter
Max Nikulin wrote: > On 02/07/2024 19:28, Dan Ritter wrote: > > iptables (which are currently implemented in nftables) don't have a native > > timeout; > > nft sets have the timeout option. Isn't it to specify interval of time to > remove elements? It works with ipset, which I always think of as

Re: timeout for iptables

2024-07-02 Thread Max Nikulin
On 02/07/2024 19:28, Dan Ritter wrote: iptables (which are currently implemented in nftables) don't have a native timeout; nft sets have the timeout option. Isn't it to specify interval of time to remove elements?

Re: timeout for iptables

2024-07-02 Thread Dan Ritter
Jeff Peng wrote: > Is there a tool for maintaining the timeout for iptables rules? > > for example, one IP would be blocked by my iptables for 24 hours, and > another IP should be blocked for one week. iptables (which are currently implemented in nftables) don't have a native timeout; you need t