### vampire-specific rules.
m4_divert(82)m4_dnl
+## Repelling evil DDos attack.
+run ipset -N ddos-evil-dns iphash 2>/dev/null || :
+run iptables -A inbound -j DROP \
+ -m set --set ddos-evil-dns src \
+ -p udp --destination-port $port_dns
+
## Externally visible services.
allowservices inbound tcp \
finger ident \