X-Git-Url: https://www.chiark.greenend.org.uk/ucgi/~mdw/git/firewall/blobdiff_plain/f98dfdf667181aad1d53a6e3a3758c2c6caec3a8..4d0888c3de7cc02ae6cc6556358eff7b86bf46d3:/vampire.m4 diff --git a/vampire.m4 b/vampire.m4 index e5ab346..2f8c105 100644 --- a/vampire.m4 +++ b/vampire.m4 @@ -37,18 +37,7 @@ m4_divert(-1) ###-------------------------------------------------------------------------- ### vampire-specific rules. -m4_divert(35)m4_dnl -errorchain ddos-evil-dns DROP -## Invalid DNS request with probably-forged sender address, with intent to -## cause DDOS. - m4_divert(82)m4_dnl -## Repelling evil DDos attack. -run ipset -N ddos-evil-dns iphash 2>/dev/null || : -run iptables -A inbound -g ddos-evil-dns \ - -m set --set ddos-evil-dns src \ - -p udp --destination-port $port_dns - ## Externally visible services. allowservices inbound tcp \ finger ident \