-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Hello.

I'm finding very good success automatically blocking an entire /24 (and
/64 for IPv6) with a >8/m over 2m and 16/h over 1h. Obviously the list
of Tor relays is whitelisted (kept up to date with the cached consensus
file that's added to an nftables set). This substantially reduces the
amount of malicious load on my relays compared to the original ruleset.

I also drop established connections once they are blacklisted, otherwise
I keep seeing the same Contabo and Hetzner IPs remaining connected and
continue using a significant amount of resources.

There seem to be no false positives as the chances that multiple people
in the same /24 would be using me as their guard and all restarting Tor
within the same few minutes is very low.

Regards,
forest
-----BEGIN PGP SIGNATURE-----

iHUEARYKAB0WIQQtr8ZXhq/o01Qf/pow+TRLM+X4xgUCambCOAAKCRAw+TRLM+X4
xtaxAQCGefZYBo3ixdwkf8iq4xVJw/MpVcSBW+6vcXXPd3xDzgEA7V0vFgo+8BCY
mR3hK2f4oheOtdjYFFKR2RM1c1+14A0=
=ZtJu
-----END PGP SIGNATURE-----
_______________________________________________
tor-relays mailing list -- [email protected]
To unsubscribe send an email to [email protected]

Reply via email to