DescriptionEugene Teo (Security Response)
2009-09-09 03:07:30 UTC
+++ This bug was initially created as a clone of Bug #483588 +++
Support for connlimit in the kernel was added in Red Hat Enterprise Linux 5 via the advisory RHSA-2009:1243. This bug was filed to ensure that we also provide support for connlimit on Red Hat Enterprise Linux 4.
# cat /etc/redhat-release
Red Hat Enterprise Linux AS release 4 (Nahant Update 8)
# uname -rm
2.6.9-89.7.EL i686
# iptables -A INPUT -p tcp --syn --dport 80 -m connlimit --connlimit-above 15 -j REJECT
iptables: No chain/target/match by that name
http://linux.chinaunix.net/bbs/viewthread.php?tid=793083###
AFAIK, the iptables package has support for connlimit, but the kernel needs to provide the required module in order for this feature to work.
This is related to bug 483588.
We will need this in 4.8.z as well.
An advisory has been issued which should help the problem
described in this bug report. This report is therefore being
closed with a resolution of ERRATA. For more information
on therefore solution and/or where to find the updated files,
please follow the link below. You may reopen this bug report
if the solution does not work for you.
http://rhn.redhat.com/errata/RHSA-2011-0263.html