From 68d5edd4d31e54b6add6d2af5b8baa0c0724a4dd Mon Sep 17 00:00:00 2001 From: Simon Ruderich Date: Sun, 7 Mar 2021 10:51:36 +0100 Subject: doc: move drop rule on a separate line in blackhole example At first I overlooked the "drop". Putting it on a separate line makes it more visible and also details the separate steps of this rule. Signed-off-by: Simon Ruderich Signed-off-by: Pablo Neira Ayuso --- doc/statements.txt | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) (limited to 'doc') diff --git a/doc/statements.txt b/doc/statements.txt index 7bb538a9..0973e5ef 100644 --- a/doc/statements.txt +++ b/doc/statements.txt @@ -712,7 +712,8 @@ nft add rule ip filter input ip saddr @blackhole counter drop # requests occurred per second and ip address. nft add rule ip filter input tcp flags syn tcp dport ssh \ add @flood { ip saddr limit rate over 10/second } \ - add @blackhole { ip saddr } drop + add @blackhole { ip saddr } \ + drop # inspect state of the sets. nft list set ip filter flood -- cgit v1.2.3