doc update: mention that banning cannot be combined with listen-clear-file

This commit is contained in:
Nikos Mavrogiannopoulos
2015-03-03 15:37:58 +01:00
parent adc8473328
commit 642edaae59
2 changed files with 8 additions and 2 deletions
+4 -1
View File
@@ -254,11 +254,14 @@ min-reauth-time = 300
# Banning clients in ocserv works with a point system. IP addresses # Banning clients in ocserv works with a point system. IP addresses
# that get a score over that configured number are banned for # that get a score over that configured number are banned for
# min-reauth-time seconds. A wrong password attempt is 10 points, # min-reauth-time seconds. By default a wrong password attempt is 10 points,
# a KKDCP POST is 1 point, and a connection is 1 point. Note that # a KKDCP POST is 1 point, and a connection is 1 point. Note that
# due to difference processes being involved the count of points # due to difference processes being involved the count of points
# will not be real-time precise. # will not be real-time precise.
# #
# Score banning cannot be reliably used when receiving proxied connections
# locally from an HTTP server (i.e., when listen-clear-file is used).
#
# Set to zero to disable. # Set to zero to disable.
max-ban-score = 50 max-ban-score = 50
+4 -1
View File
@@ -324,11 +324,14 @@ min-reauth-time = 120
# Banning clients in ocserv works with a point system. IP addresses # Banning clients in ocserv works with a point system. IP addresses
# that get a score over that configured number are banned for # that get a score over that configured number are banned for
# min-reauth-time seconds. A wrong password attempt is 10 points, # min-reauth-time seconds. By default a wrong password attempt is 10 points,
# a KKDCP POST is 1 point, and a connection is 1 point. Note that # a KKDCP POST is 1 point, and a connection is 1 point. Note that
# due to difference processes being involved the count of points # due to difference processes being involved the count of points
# will not be real-time precise. # will not be real-time precise.
# #
# Score banning cannot be reliably used when receiving proxied connections
# locally from an HTTP server (i.e., when listen-clear-file is used).
#
# Set to zero to disable. # Set to zero to disable.
max-ban-score = 50 max-ban-score = 50