#Create sys-flood chain for detecting Denial of Service attacks
iptables -t nat -N syn-flood
#Limit 12 connections per sencond (burst to 24)
iptables -t nat -A syn-flood -m limit --limit 12/s --limit-burst 24 -j RETURN
iptables -t nat -A sys-flood -j DROP
#Check for Dos attack
iptables -t nat -A PREROUTING -i $EXT_IFACE -d $DEST_IP -p tcp --syn -j syn-flood
不好意思,有处笔误,已改正