1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Help with connlimits

Discussion in 'Tomato Firmware' started by gutsman7, Feb 29, 2012.

  1. gutsman7

    gutsman7 Networkin' Nut Member

    Hey everyone I have a few routers running an array of firmwares from ddwrt to toastmans latest and last but never least teddys own tomatousb firm. The problem im having is that I can limit tcp and udp on my other routers but it happens that my WRT310N V2 running teddys tomato-K26-1.28.9051MIPSR2-beta22-Mini.trx is not limiting these conns. I have tried various scripts that work for my other routers in different locations but not on this one. Here are some scripts ive tried that work great on my other routers.
    iptables -t nat -I PREROUTING -p tcp —syn -m iprange —src-range -m connlimit —connlimit-above 80 -j DROP this one does nothing at all
    iptables -I FORWARD -s -p tcp -m connlimit --connlimit-above 40 -j DROP
    iptables -I FORWARD -s -p tcp -m connlimit --connlimit-above 40 -j LOG --log-prefix "would drop: " for single ips this one sends my router in a reboot loop.
    iptables -I FORWARD -s -p tcp -m connlimit --connlimit-above 60 -j DROP
    iptables -I FORWARD -s -p tcp -m connlimit --connlimit-above 60 -j DROP these also send my router into a endless reboot cycle. Note that I always perform full nvram erase before and after flashing so thats not the matter. Any script thrown this way is greatly welcomed.

Share This Page