kern/189720: [ipfw] [patch] pps action for ipfw

Dewayne Geraghty dewayne.geraghty at heuristicsystems.com.au
Sat May 31 05:11:56 UTC 2014


What is the "use case" of this addition?  Is this objective to limit the
mischief on a certain port, for example ntp or port 53?

I can appreciate the need to limit the number of packets during, say a
DDOS event, but I'm struggling with why I would want less that 1 packet
per second. 

Is the idea of pps meant to remove the need of dummynet where it is used
in almost trivial cases?  Though if this were the case, then bps (bits
per second) may be more useful? 

Dewayne.



More information about the freebsd-ipfw mailing list