I noticed that you can create state limits using the virusprot alias in firewall rules to help prevent against potential abuse or attacks but I'm a bit confused about the set up process.
In the advanced setting on firewall rules I'm assuming you enter the maximum source connections then below that you set the virusprot alias as the overload table option. But I've noticed that all my IP type aliases are also listed as options for the overload table?
What I'm confused about is what the virusprot alias actually is? It's listed as dynamic when viewed with the list of aliases I've created myself.
Also what would happen if I put an IP type alias I've created as an option for the overload table when creating a state limit? Would it limit maximum states only for those source networks/IPs?
I see there is also an automatically generated rate limit rule that is created when the checkbox 'Disable rate limit rule' is unchecked (default) which also uses the virusprot alias as the source address.
Thanks in advance for any help as I'm by no means an expert. I've recently moved from pfSense and it's great to be able to support the project directly so I've been donating €10/month to show my appreciation.