Good day, ladies and gentlemen. Tell me how to cope with this problem: Gentoo Linux 2.6.37-hardened-r2, which NATит certain IP addresses in the subnet. How to restrict the traffic to those IP, and some of them ***evout and clog the entire channel.
You can use tc for this, although I can not be sure what to Ghent this will be the most convenient way.
Ie you need the shaping. To do this in Linux is tc. You can write rules tc hands, and you can use the example script htbinit. It generates rules tc on the basis of more or less readable configs.
For a start, limit = allow or disallow, but to limit?

If the first — then iptables-A FORWARD -s address -j DROP
If the second — that the tc sort it out, it's really difficult. Finished you may find the initscripts in the Gent no, your write is quite real.
I usually just dropou this type of connection, every fifth packet and say that the network is congested, people are always themselves to its senses and does not overwhelm. Social engineering what can I say.

