Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
25% Recurring Discount on NVMe VPS
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
CloudLinux
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

Bandwidth-optimized VPS in Switzerland

2»

Comments

  • rpqurpqu Member
    edited July 20

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:
    @forest who was @aluy's upstream?

    Hi, Datasource AG (AS51396)

    When are you going to add this to your signature

    remarks: ^^ if you dont like those, go away ^^

    almost forgot i wanted to move that below the descr

    While we're at it, let's add lain to your bgp.tools profile picture like @beanman109
    https://lowendtalk.com/discussion/219109/i-am-being-censored-by-bgp-tools#latest

    honestly how did he do this

    Here

    @beanman109 said:

    @forest said:
    I wonder if changing the picture (even by one pixel) will cause the filter to be reset. You could give it a try...

    you can't even upload pictures onto bgp.tools
    they scrape the website listed for your asn from peeringdb and screenshot it once a week so i serve the IP ranges that scrape the site a specific image

    i usually change it every couple weeks when i remember that i have an ASN

    @beanman109 said:

    @forest said:
    That's actually hilarious.

    I wonder if an actual person saw that and got offended or if they had some AI flag it.

    it was flagged from someone in the ipv6 networking discord apparently
    i also heard it made the rounds in a telegram chatgroup aswell

  • aluyaluy Member, Patron Provider

    @rpqu said:

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:
    @forest who was @aluy's upstream?

    Hi, Datasource AG (AS51396)

    When are you going to add this to your signature

    remarks: ^^ if you dont like those, go away ^^

    almost forgot i wanted to move that below the descr

    While we're at it, let's add lain to your bgp.tools profile picture like @beanman109
    https://lowendtalk.com/discussion/219109/i-am-being-censored-by-bgp-tools#latest

    honestly how did he do this

    Here

    @beanman109 said:

    @forest said:
    I wonder if changing the picture (even by one pixel) will cause the filter to be reset. You could give it a try...

    you can't even upload pictures onto bgp.tools
    they scrape the website listed for your asn from peeringdb and screenshot it once a week so i serve the IP ranges that scrape the site a specific image

    i usually change it every couple weeks when i remember that i have an ASN

    @beanman109 said:

    @forest said:
    That's actually hilarious.

    I wonder if an actual person saw that and got offended or if they had some AI flag it.

    it was flagged from someone in the ipv6 networking discord apparently
    i also heard it made the rounds in a telegram chatgroup aswell

    funny way of doing it, maybe could also do just showing the bgp.tools scraper only that pic

  • rpqurpqu Member
    edited July 20

    @aluy said:
    funny way of doing it, maybe could also do just showing the bgp.tools scraper only that pic

    Yea
    my suggestions





    Thanked by 3aluy forest buggedout
  • forestforest Member

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:
    @forest who was @aluy's upstream?

    Hi, Datasource AG (AS51396)

    When are you going to add this to your signature

    remarks: ^^ if you dont like those, go away ^^

    almost forgot i wanted to move that below the descr

    While we're at it, let's add lain to your bgp.tools profile picture like @beanman109
    https://lowendtalk.com/discussion/219109/i-am-being-censored-by-bgp-tools#latest

    honestly how did he do this

    The bgp.tools scraper periodically connects to the website and screenshots it. He just made his website show a full image but only to the scraper IP. And YES you should totally put in Lain that way!!

    Thanked by 2rpqu buggedout
  • forestforest Member
    edited July 20

    @aluy said:

    @JohnFilch123 said:

    @aluy said:

    @rpqu said:

    @aluy said:

    @rpqu said:
    @forest who was @aluy's upstream?

    Hi, Datasource AG (AS51396)

    When are you going to add this to your signature

    remarks: ^^ if you dont like those, go away ^^

    almost forgot i wanted to move that below the descr

    Are you planning to resurrect Swiss location? Or gone indefinitely?

    at current point i dont see how

    What was the cause of the move? I know there was a large-scale DDoS shortly before. Did they kick you out because a customer kept attracting DDoS attacks against their infra or something?

    @ZeroAnarchy said:
    @forest

    UP-NETWORK (Swiss hoster) is fully suitable for your requirements:

    2vCPU
    4GB RAM
    20GB SSD
    Unlimited 100Mbps
    Dual stack (IPv4 and IPv6 /64 subnet)
    DDoS Protection included

    Their ToS says nothing about banning VPNs, TOR, or BitTorrent.
    I kept the I2P router turned on for 30 days, and everything worked fine.

    It is possible to pay in cryptocurrency.

    The annual payment (with a 10% discount) plus the commission (7%) of the payment gateway is approximately $36/year (without VAT).

    Website: https://up-network.ch/services/vps-hosting
    LG: https://looking.house/companies/up-network-ch/looking-glass

    I have been using a similar VPS for several months now, there are no problems.
    There was only a problem with their billing, but it was solved through support.

    Looks good to me! Very good specs too for only $36/year. Does anyone have an affiliate link they'd like me to use?

    @oloke said:

    @ZeroAnarchy said:
    @forest

    UP-NETWORK (Swiss hoster) is fully suitable for your requirements:

    Possibly related:
    https://lowendtalk.com/discussion/214590/up-network-ch-reviews

    @Nekopara

    Looks like his only issue was NVMe reliability. I don't have much of a concern about that, as long as it can beat the 80% uptime of my DeluxHost boxen. But good to know!

    Thanked by 3oloke Killix buggedout
  • forestforest Member

    @rpqu said:

    @aluy said:
    funny way of doing it, maybe could also do just showing the bgp.tools scraper only that pic

    Yea
    my suggestions





    @aluy Use this one and I'll love you forever:

    aluy

    Original for reference:

    lain

    Thanked by 4Killix aluy oloke rpqu
  • @forest

    @forest said:

    Looks good to me! Very good specs too for only $36/year. Does anyone have an affiliate link they'd like me to use?

    They don't have an affiliate program right now.

    If you order a VPS there, I can give you a couple of tips:

    1) Manually limit the speed in the torrc config to the guaranteed speed in the tariff plan, since all tariffs are connected to a 10 Gbps link. The provider allows only short-term exceeding of the speed above the tariff plan, with frequent exceeding (I am sure that the TOR relay consumes a lot of traffic), the provider will manually cut your speed to the guaranteed one, so it is better to limit yourself than constantly abuse the hoster's link.

    2) Check the website with the hoster's documentation, there is interesting information there. For example, it advises not to enable IPv6 support when ordering a VPS, but to do so after it is created. The documentation also specifies limits on TCP connections and other things.

    3) If you will pay in cryptocurrency (I pay via Bitcoin Lightning), then I recommend using the method through "Payssion" (with a 7% commission). When I paid via "Payrexx" (4% commission) there were problems with depositing money in billing, and then the option of paying with cryptocurrency disappeared in this method altogether (apparently removed because of these problems).

    4) External scanners will always show that all ports on the server are open, even if you have blocked everything in iptables/nftables. I believe this is due to the DDoS protection of the hoster, such as protection against TCP-SYN flood and the like.

    Otherwise, I personally have not encountered any critical technical problems with the VPS during a couple of months of use.
    I do daily backups through Restic+Rclone, so I have nothing to be afraid of.

    This hoster started working only in August last year, it is not advertised here on LowEndTalk at all, so they don't have many clients.
    At the beginning of the work, there may have been network problems (judging by the historical records of their Status page), some even lost data, as they say here, but now I think their work has stabilized.

    Thanked by 1forest
  • forestforest Member
    edited 12:26AM

    @ZeroAnarchy said: The documentation also specifies limits on TCP connections and other things.

    Uh oh! Tor likes a lot of TCP connections:

    root@forest-xhosts-1-uk:~# ss -s
    Total: 10295
    TCP:   10204 (estab 10187, closed 1, orphaned 3, timewait 1)
    
    Transport Total     IP        IPv6
    RAW       0         0         0
    UDP       4         3         1
    TCP       10203     7456      2747
    INET      10207     7459      2748
    FRAG      0         0         0
    

    https://docs.up-network.ch/documentation/vps/vps/network-restrictions-isolation-and-abuse-policy

    So 50k connections total and 250 new connections per second? It might only be referring to new outbound ports though? Not sure, I'll ask them. Either way, that's not enough as low-bandwidth DDoS attacks can often increase the number far beyond 50k. If they can't or won't create an exception, then it may not be suitable for my needs.

  • forestforest Member

    @ZeroAnarchy said: 4) External scanners will always show that all ports on the server are open, even if you have blocked everything in iptables/nftables. I believe this is due to the DDoS protection of the hoster, such as protection against TCP-SYN flood and the like.

    How is that even possible? Does it monitor for an ACK and if it doesn't see any within a short timeframe, it spoofs an ACK?

  • rpqurpqu Member

    @forest sounds like it will be harder challenge than you thought

    Thanked by 1concept
  • forestforest Member

    @rpqu said:
    @forest sounds like it will be harder challenge than you thought

    Could be, but Swizerland is in the EU in a place with lots of cheap bandwidth, so I'm sure it'll be easier to find a good deal than if I were looking for those specs in APAC for the same price. So I remain optimistic.

  • conceptconcept Member
    edited 1:00AM

    @forest said:

    Uh oh! Tor likes a lot of TCP connections:

    root@forest-xhosts-1-uk:~# ss -s
    Total: 10295
    TCP:   10204 (estab 10187, closed 1, orphaned 3, timewait 1)
    
    Transport Total     IP        IPv6
    RAW       0         0         0
    UDP       4         3         1
    TCP       10203     7456      2747
    INET      10207     7459      2748
    FRAG      0         0         0
    

    https://docs.up-network.ch/documentation/vps/vps/network-restrictions-isolation-and-abuse-policy

    So 50k connections total and 250 new connections per second? It might only be referring to new outbound ports though? Not sure, I'll ask them. Either way, that's not enough as low-bandwidth DDoS attacks can often increase the number far beyond 50k. If they can't or won't create an exception, then it may not be suitable for my needs.

    That is just silly imo..

    Total: 55792
    TCP:   55675 (estab 55128, closed 30, orphaned 236, timewait 30)
    
    Transport Total     IP        IPv6
    RAW       0         0         0        
    UDP       7         5         2        
    TCP       55645     43838     11807    
    INET      55652     43843     11809    
    FRAG      0         0         0        
    
  • forestforest Member

    @concept said:

    @forest said:

    Uh oh! Tor likes a lot of TCP connections:

    root@forest-xhosts-1-uk:~# ss -s
    Total: 10295
    TCP:   10204 (estab 10187, closed 1, orphaned 3, timewait 1)
    
    Transport Total     IP        IPv6
    RAW       0         0         0
    UDP       4         3         1
    TCP       10203     7456      2747
    INET      10207     7459      2748
    FRAG      0         0         0
    

    https://docs.up-network.ch/documentation/vps/vps/network-restrictions-isolation-and-abuse-policy

    So 50k connections total and 250 new connections per second? It might only be referring to new outbound ports though? Not sure, I'll ask them. Either way, that's not enough as low-bandwidth DDoS attacks can often increase the number far beyond 50k. If they can't or won't create an exception, then it may not be suitable for my needs.

    That is just silly imo..

    Total: 55792
    TCP:   55675 (estab 55128, closed 30, orphaned 236, timewait 30)
    
    Transport Total     IP        IPv6
    RAW       0         0         0        
    UDP       7         5         2        
    TCP       55645     43838     11807    
    INET      55652     43843     11809    
    FRAG      0         0         0        
    

    Are you running multiple Tor processes or is it something else? I've never seen that much except when under attack.

  • rpqurpqu Member
    edited 1:32AM

    fug

    @forest said:

    @rpqu said:
    @forest sounds like it will be harder challenge than you thought

    Could be, but Swizerland is in the EU in a place with lots of cheap bandwidth, so I'm sure it'll be easier to find a good deal than if I were looking for those specs in APAC for the same price. So I remain optimistic.

    Technically not part of EU and has very high labor cost. Hopefully you'd find new host

  • @forest Really, it's better to ask them, the limits here are not entirely clear.

    TCP: 10204 (estab 10187, closed 1, orphaned 3, timewait 1)

    TCP: 55675 (estab 55128, closed 30, orphaned 236, timewait 30)

    Are you running multiple Tor processes or is it something else? I've never seen that much except when under attack.

    DDoS attacks on TOR don't happen every day, in a normal period, I think 50,000 TCP connections are enough (the cheap tariff still only has 100Mbps bandwidth, a lot of users won't fit there).
    In any case, you can manually set a global limit on the number of established TCP connections via iptables/nftables. In this case, at least the hoster will not suddenly limit your traffic.
    The rest of the time, the relay will work fine.

    How is that even possible? Does it monitor for an ACK and if it doesn't see any within a short timeframe, it spoofs an ACK?

    Something like that, but the details of how it works are not written anywhere.
    This came as a surprise to me: my firewall rules showed closed ports for my previous hoster, but for this one (with the same rules), all ports were open. But the previous hoster did not have DDoS protection.

    If you look for another hoster with a server in Switzerland, then the characteristics will obviously be 2 times lower, and the price is 2 times higher.
    All the offers I've seen have been priced at $6-10/month for a VPS in Switzerland. Clearly beyond your requirements.
    You can order a VPS for a month there for the test and see what happens. And then change to an annual payment if you want to stay.

  • forestforest Member
    edited 2:22AM

    @ZeroAnarchy said: DDoS attacks on TOR don't happen every day, in a normal period, I think 50,000 TCP connections are enough (the cheap tariff still only has 100Mbps bandwidth, a lot of users won't fit there).
    In any case, you can manually set a global limit on the number of established TCP connections via > iptables/nftables. In this case, at least the hoster will not suddenly limit your traffic.
    The rest of the time, the relay will work fine.

    They happen a lot more than you might think, but they don't cripple the whole network. There's one going on right now, actually, targeting a subset of guards. It doesn't bring the relays down completely, but it causes the CPU to overload (each NTor handshake is expensive) so that it struggles to take more legitimate connections. Even at 2M connections, some relays can (just barely) continue functioning. But if it had to stop accepting connections at 50k, then it would always become unusable the moment a DDoS occurs even while it has plenty of CPU power remaining.

    Currently I just limit each IP to have no more than 8 simultaneous connections to the relay, and add any IP that attempts more than 8 new connections in a 2 minute period or 32 new connections in a 1 hour period to a 24 hour blacklist. It works fairly well against most relay overload attacks, including the current one.

    @ZeroAnarchy said: Something like that, but the details of how it works are not written anywhere.
    This came as a surprise to me: my firewall rules showed closed ports for my previous hoster, but for this one (with the same rules), all ports were open. But the previous hoster did not have DDoS protection.

    That'll interfere with port knocking and might also cause issues if it causes other relays to get stuck trying to connect to mine while mine is down for a reboot. I wonder what happens when it reboots and suddenly sees a remote IP sending an unexpected SYN/ACK. It'll probably reply with RST and kill the connection, whereas if the provider didn't spoof connections, the remote IP would still be re-sending SYNs every once in a while until the relay is up and acknowledges the attempt.

    I have no idea how clients and other relays would handle a situation where the connections suddenly malfunction with spoofed acknowledgements when the relay reboots, rather than going unanswered. It might even get my relay blacklisted if it appears to be a DoS attempt (by tricking clients into holding open spoofed connections that won't actually speak the Tor protocol).

    @ZeroAnarchy said: @forest Really, it's better to ask them, the limits here are not entirely clear.

    Yep, I will. If they can make an exception for me, I'll go with them. Otherwise I'll keep looking, even if I have to up my budget.

  • buggedoutbuggedout Member

    @forest said:
    Looks good to me! Very good specs too for only $36/year. Does anyone have an affiliate link they'd like me to use?

    Tell me how it is after a week, I was planning to try them few months ago but seeing no reviews I dropped the idea.

  • forestforest Member

    @buggedout said:

    @forest said:
    Looks good to me! Very good specs too for only $36/year. Does anyone have an affiliate link they'd like me to use?

    Tell me how it is after a week, I was planning to try them few months ago but seeing no reviews I dropped the idea.

    I've emailed them to see if they can loosen their TCP connection restrictions, otherwise it might not be a good fit for me after all.

    Thanked by 1buggedout
  • conceptconcept Member

    @forest said:
    Are you running multiple Tor processes or is it something else? I've never seen that much except when under attack.

    Yes multiple processes and there is an ongoing attack going on across the tor network.

  • forestforest Member
    edited 2:57AM

    @concept said:

    @forest said:
    Are you running multiple Tor processes or is it something else? I've never seen that much except when under attack.

    Yes multiple processes and there is an ongoing attack going on across the tor network.

    Yep, it's coming from Contabo IPs. Consider using toalf's tor-ddos mitigation script if you use iptables. I'm deploying it across more of my fleet now and it's catching most of the attacks while leaving legitimate traffic untouched.

    At its simplest, the current attack can be largely stopped by limiting simultaneous connections to the ORPort to 8 per IP.

  • @forest said: toalf's tor-ddos mitigation script

    This one?

    Thanked by 1forest
  • forestforest Member

    @JohnFilch123 said:

    @forest said: toalf's tor-ddos mitigation script

    This one?

    Different one, this one: https://github.com/toralf/torutils

    The Enkidu one is no longer maintained because the owner is dead or about to be.

    Thanked by 1JohnFilch123
  • @forest said:

    @JohnFilch123 said:

    @forest said: toalf's tor-ddos mitigation script

    This one?

    Different one, this one: https://github.com/toralf/torutils

    The Enkidu one is no longer maintained because the owner is dead or about to be.

    You can't just write something so ominous and not specify if it's for a natural or not so natural reason

  • forestforest Member
    edited 7:12AM

    @Mainfrezzer said:

    @forest said:

    @JohnFilch123 said:

    @forest said: toalf's tor-ddos mitigation script

    This one?

    Different one, this one: https://github.com/toralf/torutils

    The Enkidu one is no longer maintained because the owner is dead or about to be.

    You can't just write something so ominous and not specify if it's for a natural or not so natural reason

    https://lists.torproject.org/mailman3/hyperkitty/list/[email protected]/thread/AEAV35JQUF5HVIZYCITIGVJOMXBEPV2F/

    On May 2, 2026 at 10:28 AM, Chris Enkidu-6 via tor-relays tor-relays@lists.torproject.org wrote:

    On my last post to the group I mentioned a serious illness.
    unfortunately I should have said a terminal illness. I probably have a
    couple of weeks.Since my original post I really had no legitimate offer
    from anyone to take it over. Just a few time waster conversations that
    went nowhere. So as of now both tor-ddos and tor-relay-lists are down.
    Sorry to do this but I have other things to worry about and since only a
    limited number of people on this list know about it. Others can judge me
    however they like.

    Thank you for reading this.

    Thanked by 2Mainfrezzer ayerfton
  • @forest said: this one

    Oh thanks, need to deploy it as well.

  • forestforest Member
    edited 8:06AM

    @JohnFilch123 said:

    @forest said: this one

    Oh thanks, need to deploy it as well.

    This is what I'm currently experimenting with, as an nftables port of toralf's script (only allows port 22 for SSH and DDoS-protected Tor on 9001, but does not support persistence, auto-updating of hardcoded safe IPs, or multiple ORPorts):

    flush ruleset
    
    table inet filter {
            set tor_ddos4 {
                    type ipv4_addr
                    flags timeout
                    timeout 24h
            }
    
            set tor_ddos6_64 {
                    type ipv6_addr
                    flags timeout
                    timeout 24h
            }
    
            set tor_ddos6_80 {
                    type ipv6_addr
                    flags timeout
                    timeout 24h
            }
    
            set tor_ddos6_128 {
                    type ipv6_addr
                    flags timeout
                    timeout 24h
            }
    
            set tor_connlimit4 {
                    type ipv4_addr
            }
    
            set tor_connlimit6_64 {
                    type ipv6_addr
            }
    
            set tor_connlimit6_80 {
                    type ipv6_addr
            }
    
            set tor_connlimit6_128 {
                    type ipv6_addr
            }
    
            define tor_trusted4 = {
                    141.212.118.18,
                    193.187.88.42,
                    193.187.88.43,
                    193.187.88.44,
                    193.187.88.45,
                    193.187.88.46,
                    45.66.35.11,
                    66.111.2.131,
                    128.31.0.39,
                    131.188.40.189,
                    171.25.193.9,
                    193.23.244.244,
                    199.58.81.140,
                    204.13.164.118,
                    216.218.219.41,
                    217.196.147.77
            }
    
            define tor_trusted6 = {
                    2a0c:dd40:1:b::42,
                    2607:f018:600:8:be30:5bff:fef1:c6fa,
                    2001:470:164:2::2,
                    2001:638:a000:4140::ffff:189,
                    2001:678:558:1000::244,
                    2001:67c:289c::9,
                    2610:1c0:0:5::131,
                    2620:13:4000:6000::1000:118,
                    2a02:16a8:662:2203::1
            }
    
            set hoster64 {
                    type ipv6_addr
                    flags interval
                    elements = {
                            2a01:4f8::/32,
                            2a01:4f9::/32,
                            2a01:4ff:ff01::/48,
                            2a03:4000::/32,
                            2a06:be80::/29,
                            2a0b:f4c2::/40,
                            2a11:e980::/29,
                            2a12:2240::/29
                    }
            }
    
            set hoster80 {
                    type ipv6_addr
                    flags interval
                    elements = {
                            2001:67c:e60::/48,
                            2607:f1c0::/32,
                            2a00:1a68::/32,
                            2a00:da00:8000::/34,
                            2a0d:7f00::/29
                    }
            }
    
            chain tor_input4 {
                    ip saddr $tor_trusted4 accept
                    meter tor-ddos-fast4 { ip saddr timeout 2m limit rate over 8/minute burst 8 packets } update @tor_ddos4 { ip saddr }
                    meter tor-ddos-slow4 { ip saddr timeout 1h limit rate over 32/hour burst 32 packets } update @tor_ddos4 { ip saddr }
                    ip saddr @tor_ddos4 drop
                    add @tor_connlimit4 { ip saddr ct count over 8 } drop
                    accept
            }
    
            chain tor_input6 {
                    ip6 saddr $tor_trusted6 accept
                    ip6 saddr @hoster64 jump {
                            meter tor-ddos-fast6-64 { ip6 saddr & ffff:ffff:ffff:ffff:: timeout 2m limit rate over 8/minute burst 8 packets } update @tor_ddos6_64 { ip6 saddr & ffff:ffff:ffff:ffff:: timeout 24h }
                            meter tor-ddos-slow6-64 { ip6 saddr & ffff:ffff:ffff:ffff:: timeout 1h limit rate over 32/hour burst 32 packets } update @tor_ddos6_64 { ip6 saddr & ffff:ffff:ffff:ffff:: timeout 24h }
                            ip6 saddr & ffff:ffff:ffff:ffff:: @tor_ddos6_64 drop
                            add @tor_connlimit6_64 { ip6 saddr & ffff:ffff:ffff:ffff:: ct count over 8 } drop
                            accept
                    }
                    ip6 saddr @hoster80 jump {
                            meter tor-ddos-fast6-80 { ip6 saddr & ffff:ffff:ffff:ffff:ffff:: timeout 2m limit rate over 8/minute burst 8 packets } update @tor_ddos6_80 { ip6 saddr & ffff:ffff:ffff:ffff:ffff:: timeout 24h }
                            meter tor-ddos-slow6-80 { ip6 saddr & ffff:ffff:ffff:ffff:ffff:: timeout 1h limit rate over 32/hour burst 32 packets } update @tor_ddos6_80 { ip6 saddr & ffff:ffff:ffff:ffff:ffff:: timeout 24h }
                            ip6 saddr & ffff:ffff:ffff:ffff:ffff:: @tor_ddos6_80 drop
                            add @tor_connlimit6_80 { ip6 saddr & ffff:ffff:ffff:ffff:ffff:: ct count over 8 } drop
                            accept
                    }
                    meter tor-ddos-fast6-128 { ip6 saddr timeout 2m limit rate over 8/minute burst 8 packets } update @tor_ddos6_128 { ip6 saddr timeout 24h }
                    meter tor-ddos-slow6-128 { ip6 saddr timeout 1h limit rate over 32/hour burst 32 packets } update @tor_ddos6_128 { ip6 saddr timeout 24h }
                    ip6 saddr @tor_ddos6_128 drop
                    add @tor_connlimit6_128 { ip6 saddr ct count over 8 } drop
                    accept
            }
    
            chain tor_input {
                    meta nfproto ipv4 jump tor_input4
                    meta nfproto ipv6 jump tor_input6
            }
    
            chain input {
                    type filter hook input priority filter; policy drop;
    
                    iif lo accept
                    ct state vmap { established : accept, related : accept, invalid : drop }
    
                    ct state new jump {
                            tcp dport 9001 tcp flags syn jump tor_input
                            tcp dport 22 accept
                    }
    
                    icmpv6 type { nd-neighbor-solicit, nd-router-advert, nd-neighbor-advert } limit rate 25/second accept
            }
    
            chain output {
                    type filter hook output priority filter; policy accept;
            }
    
            chain forward {
                    type filter hook forward priority filter; policy drop;
            }
    }
    
    Thanked by 2oloke JohnFilch123
Sign In or Register to comment.