1state limiter dns-server id 1 limit 1000 rate 1/10 2pass in proto tcp from any to any port = domain flags S/SA keep state state limiter id 1 (no-match) 3