Richard wrote: > These look correct to me, but I usually use iptables via shorewall. > > That said, those are massive subnets to block. I guess if we're blocking > legitimate users, we'll hear about it. >
If the blocks seem to work I was thinking of announcing to users list the blocked ranges, together with an explanation. Separately, I was thinking of unblocking some of the ranges to see if the server still works after a few days. We still don't know why we run low on memory, ie if its related to Trac, a wiki or git or something else. So if the server starts losing memory, I can see the IP of the culprit and then perhaps figure out which of our services that has the memory leak. Cheers, Christian > > Richard > >