i need to limit number of simultaneous connections to httpd:

on server:
iptables -A INPUT -p tcp -m connlimit --connlimit-above 5 --dport 80 -j DROP
(there is onle one rule in firewall )

on client i run slowloris..

on the server under attack
netstat -nta | grep :80 | grep ESTABLISHED | wc -l

as i understand 'iptables -L -n -v' - my rule never hits,

existing behavior:
on server under attack a lot of simultaneous connection from single ip.

expected behavior:
server should have only 5 connections

i miss something ?


debian linux 2.6.30-2, iptables 1.4.4-2 
slowloris - http://ha.ckers.org/slowloris/

