<div dir="ltr">My bad, i meant "rate_filter" and not "rate_limit".<div>I'll check if "rate_filter" is supported.</div><div><br></div><div>Thank you Victor</div></div><div class="gmail_extra">
<br><br><div class="gmail_quote">On Tue, Feb 11, 2014 at 3:25 PM, Victor Julien <span dir="ltr"><<a href="mailto:lists@inliniac.net" target="_blank">lists@inliniac.net</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">
<div class="">On 02/11/2014 02:54 PM, Aline Shir wrote:<br>
> I'm looking for a way to block ip addresses performing syn flood on my<br>
> network.<br>
><br>
> I've seen some exemple rules, like this one:<br>
> alert tcp !$HOME_NET any -> $HOME_NET 80 (flags: S; msg:"Possible TCP<br>
> DoS"; flow: stateless; threshold: type both, track by_src, count 70,<br>
> seconds 10; sid:10001;rev:1;)<br>
><br>
> The rule seems to trigger correctly. What i'm looking for, is something<br>
> like snort's rate_limit filter that blocks the source ip for n seconds<br>
> if it triggers the above rule x times.<br>
<br>
</div>Have you tried using rate_limit? We support the keyword, so it should<br>
work like in Snort.<br>
<span class="HOEnZb"><font color="#888888"><br>
--<br>
---------------------------------------------<br>
Victor Julien<br>
<a href="http://www.inliniac.net/" target="_blank">http://www.inliniac.net/</a><br>
PGP: <a href="http://www.inliniac.net/victorjulien.asc" target="_blank">http://www.inliniac.net/victorjulien.asc</a><br>
---------------------------------------------<br>
<br>
_______________________________________________<br>
Suricata IDS Users mailing list: <a href="mailto:oisf-users@openinfosecfoundation.org">oisf-users@openinfosecfoundation.org</a><br>
Site: <a href="http://suricata-ids.org" target="_blank">http://suricata-ids.org</a> | Support: <a href="http://suricata-ids.org/support/" target="_blank">http://suricata-ids.org/support/</a><br>
List: <a href="https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users" target="_blank">https://lists.openinfosecfoundation.org/mailman/listinfo/oisf-users</a><br>
OISF: <a href="http://www.openinfosecfoundation.org/" target="_blank">http://www.openinfosecfoundation.org/</a><br>
</font></span></blockquote></div><br></div>