Hello I have this rule:
-I INPUT -m string --hex-string "|XXX|" --algo bm --dport 7777 -j DROP
work's but there is some false positive.
So I want to limit this rule to 5 connections accepted by second before to drop the rest AND if the ip is already connected ( +1 limit), accept other packets with the even ip.
Thanks to help.