I think the more relevant connection list can be seen withI guess you don't need --connlimit-mask in your rule.2- I also used --connlimit-mask 32, but the result is the same.Why do you think so ?... I think this command is based on session and not IP address. ...What does netstat tell you ?When I change the number 2 to 20, the client can access the Internet through the proxy.
Code:
conntrack -L
Code:
ss
Statistics: Posted by lindi — 2024-02-15 20:37 — Replies 4 — Views 104