]> git.ipfire.org Git - people/pmueller/ipfire-2.x.git/commit
firewall: raise log rate limit to 10 packets per second
authorPeter Müller <peter.mueller@ipfire.org>
Mon, 29 Jul 2019 20:00:00 +0000 (20:00 +0000)
committerArne Fitzenreiter <arne_f@ipfire.org>
Tue, 20 Aug 2019 17:22:48 +0000 (17:22 +0000)
commit8ee3a135527707f60baa948e35b78187787bc9f7
tree20efb5afd30e4e1d3fa1a2df67d2c447896ea9b8
parentd111587cc3b0007b35c09dd847d035e6ffadffc7
firewall: raise log rate limit to 10 packets per second

Previous setting was to log 10 packets per minute for each
event logging is turned on. This made debugging much harder,
as the limit was rather strict and chances of dropping a
packet without logging it were good.

This patch changes the log rate limit to 10 packets per
second per event, to avoid DoS attacks against the log file.
I plan to drop log rate limit entirely in future changes,
if a better solution for this attack vector is available.

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
Cc: Tim FitzGeorge <ipfr@tfitzgeorge.me.uk>
Cc: Michael Tremer <michael.tremer@ipfire.org>
Signed-off-by: Arne Fitzenreiter <arne_f@ipfire.org>
src/initscripts/system/firewall