[dnsdist] print the ip address that match a Packet Actions
antoine.blin at gandi.net
Fri Oct 1 08:06:53 UTC 2021
Thank you for your TIP. It works.
On 28/09/2021 11:27, Remi Gacogne via dnsdist wrote:
> Hi Antoine,
> On 9/27/21 14:00, antoine blin via dnsdist wrote:
>> I'm using the rule : "addAction(MaxQPSIPRule(5), DropAction())" and
>> I'm wondering if it is possible to see, through the console API or
>> other API, the list of subnet in which rate limit rule is applied.
> Not directly, I'm afraid, but you could work something out by setting
> a tag when that rule matches, then trigger a LogAction  and finally
> a DropAction when the tag is set. Something like (untested, but you
> should get the idea):
> addAction(MaxQPSIPRule(5), SetTagAction("max-qpsip-rule", "match"))
> addAction(TagRule("max-qpsip-rule", "match"),
> addAction(TagRule("max-qpsip-rule", "match"), DropAction())
> Note that this works because LogAction does not stop the processing of
> subsequent rules, as most actions do.
> : https://dnsdist.org/rules-actions.html#LogAction
> Best regards
> dnsdist mailing list
> dnsdist at mailman.powerdns.com
-------------- next part --------------
An HTML attachment was scrubbed...
More information about the dnsdist