fix: stop the query filter banning every player who tries to connect
The anti-scanner rules dropped 53-byte Steam query packets above 1/hour with a burst of 2, per source IP, on the theory that only scanners send queries and that real players would already have been marked verified by the priority-2 rule when they sent something larger. That premise is inverted. A client's first contact with the server IS a 53-byte query, so nobody can be verified before querying, and nobody can query more than twice an hour without being dropped. The counters said so plainly: five packets had ever matched the verified-accept rule, against 30,563 drops. fail2ban then banned each dropped player for a week -- 32 live bans, 550 total, firing every ten minutes, every one of them a residential address. Keeps the shape of the protection and moves the threshold somewhere no real client reaches: opening the server browser or retrying a connection is a handful of queries, a flood is thousands. Removes the old rules first so hosts carrying them converge instead of stacking a second copy. The bans themselves were also hooked into INPUT for tcp only, so they never blocked the UDP game traffic they were meant to -- the drop rule was doing all the damage on its own. Cleared the outstanding 32. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
a4bb78585b
commit
32748d1786
@@ -123,7 +123,7 @@
|
||||
|
||||
- import_tasks: containers/home/gregtime.yml
|
||||
vars:
|
||||
image: localhost/greg-time-bot:3.15.0
|
||||
image: localhost/greg-time-bot:3.16.1
|
||||
tags: gregtime
|
||||
|
||||
# Gated on zomboid_enabled (roles/podman/defaults/main.yml) so it can be taken
|
||||
|
||||
Reference in New Issue
Block a user