1iptables-translate -A INPUT -m connlimit --connlimit-above 2 2nft 'add set ip filter connlimit0 { type ipv4_addr; flags dynamic; }' 3nft 'add rule ip filter INPUT add @connlimit0 { ip saddr ct count over 2 } counter' 4 5iptables-translate -A INPUT -m connlimit --connlimit-upto 2 6nft 'add set ip filter connlimit0 { type ipv4_addr; flags dynamic; }' 7nft 'add rule ip filter INPUT add @connlimit0 { ip saddr ct count 2 } counter' 8 9iptables-translate -A INPUT -m connlimit --connlimit-upto 2 --connlimit-mask 24 10nft 'add set ip filter connlimit0 { type ipv4_addr; flags dynamic; }' 11nft 'add rule ip filter INPUT add @connlimit0 { ip saddr and 255.255.255.0 ct count 2 } counter' 12 13iptables-translate -A INPUT -m connlimit --connlimit-upto 2 --connlimit-daddr 14nft 'add set ip filter connlimit0 { type ipv4_addr; flags dynamic; }' 15nft 'add rule ip filter INPUT add @connlimit0 { ip daddr ct count 2 } counter' 16