Ipsets Blacklist Hardcoded Limitation

Thanks a million for this new release !

I enjoy very much the version upgrade on NC for example :slight_smile:

The only thing I had to do, if override the hard-coded limitation of “maxelem” in “/usr/share/nethserver-blacklist/load-ipsets” line: 111.

The machine I use is very happy with 8388608 instead of 131072 .

That is an arbitrary limit: https://github.com/NethServer/nethserver-blacklist/commit/3c72879dd258c8e65dfe05ff92cc3bd11a82d2d0
I did some researches before setting it, and the current value seemed a good compromise between performance and used memory.

We could increase it but I fear memory problem on small machines.

What do you think @dev_team?

Not an expert, but we are using double the default value, I think 128k IPs is a high number.
I think we could accept a patch reading a prop for maxelem.

2 Likes

on my todo

Merci chef(s) !

2 Likes

something to test, please come on

2 Likes

@gpunk the update has been released and will be soon available on mirrors.

The doc is available here: https://docs.nethserver.org/projects/nethserver-devel/en/latest/nethserver-blacklist.html#configuration

1 Like

Thank you very much,
It works like a charm .

Cheers

2 Likes