Internal Program Version: ipset 7.19 (The man files)
IP sets are a framework inside the Linux kernel, which can be administered by
the ipset utility. Depending on the type, currently an IP set may store IP
addresses, (TCP/UDP) port numbers or IP addresses with MAC addresses in a way,
which ensures lightning speed when matching an entry against a set.
ipset can:
* store multiple IP addresses or port numbers and match against the collection
by iptables in one swoop
* dynamically update iptables rules against IP addresses or ports without
performance penalty
* express complex IP address and ports based rulesets with one single iptables
rule and benefit from the speed of IP sets
https://ipset.netfilter.org
|