Is there a way to add destination IPs which has over 10,000 pps to the address list ?
anyone ?
For TCP and UDP traffic it would be possible to use connection rate to add addresses to a list based on total (in & out) connection rate. I’m not sure if there is a way to do it based on actual packet rate.
I am trying with the “limit” paramater on ip>firewall>filter but no luck.
I remember that dst-limit was having some issues a while back - not sure about limit. I will have a look at some filters and see if I can swap one of mine to use limit temporarily.