delonix net l4guard

Guarda de DDoS L4 à entrada — rate de ligação por origem e tecto de concorrentes.

The inbound L4 DDoS guard — per-source connection rate and a concurrent cap.

Um guarda GLOBAL (não por-container) contra rajadas de ligações novas ou um único par IP:porta a esgotar as slots do slirp único do ingress — a fronteira antes de qualquer firewall por-container. Só alcançável por manifesto (kind: L4Guard) até esta versão; net l4guard status mostra se está activo, com os contadores de descarte.

A GLOBAL guard (not per-container) against bursts of new connections or a single IP:port pair exhausting the ingress's single slirp's slots — the boundary before any per-container firewall. Only reachable via manifest (kind: L4Guard) until this version; net l4guard status shows whether it is active, with its drop counters.

Usage: delonix net l4guard [OPTIONS] <COMMAND>

Commands:
  status  Show whether the guard is active, with its drop counters
  clear   Turn the guard off
  set     Turn the guard on (or update it): new conns/s and concurrent conns, per source IP
  help    Print this message or the help of the given subcommand(s)

Options:
      --l18n <en|pt>
          Output language: `en` (default) or `pt` (Portuguese, pt_AO). Also settable via `$DELONIX_L18N`. Global — works before any subcommand

  -h, --help
          Print help (see a summary with '-h')

COMMAND MAP:
  Inspect    status
  Configure  set · clear

EXAMPLES:
  # turn on the ingress-wide DDoS guard: at most 20 new connections/s and 100
  # concurrent connections per source IP
  delonix net l4guard set 20 100

  # check whether it's actually doing anything, with its drop counters
  delonix net l4guard status

  # turn it off
  delonix net l4guard clear

SEE ALSO:
  delonix net ingress ls · delonix net egress net · delonix net netns status

  delonix › net › l4guard