Limit represents an nftables expression for rate limiting packets or bytes. It allows controlling the maximum sustained rate and burst size for traffic.
Fields
| Field Name | Description |
|---|---|
type - NftLimitType!
|
The type of limit to apply: based on packets or bytes. |
rate - Uint64!
|
The maximum average rate, in units defined by 'type' and 'unit'. For example, 100 packets per second or 1 MB per minute. |
over - Boolean!
|
If true, the limit is checked in "over" mode, meaning the rule matches when the rate exceeds the limit. If false, it matches when the rate is below the limit. |
unit - NftLimitTime!
|
The time unit for the rate limit (e.g., SECOND, MINUTE). |
burst - Uint32!
|
The maximum burst size allowed, in units defined by 'type'. This specifies how many packets/bytes can exceed the average rate before throttling. |
Used by
ChainExpressionunion: A union of all possible nftables chain expression types.
Example
Example
{
"type": "PACKETS",
"rate": "8589934592",
"over": true,
"unit": "SECOND",
"burst": "1073741824"
}