Limit request rate in Tengine to block brute force attack
2026-09-29
AdSense Slot
Rate limiting protects your web and API endpoints from brute force login attempts and request flood.
Config example
Add in http section:
limit_req_zone $binary_remote_addr zone=api_limit:10m rate=10r/s;
Inside server/location block:
location /login {
limit_req zone=api_limit burst=20 nodelay;
proxy_pass http://backend;
}
- zone=api_limit:10m allocate shared memory zone 10MB
- rate=10r/s allow maximum 10 requests per second per IP
Test the rule
Use curl to send mass request for test. Do not run attack on production site.
Notes
- Rate limit based on IP works for most small site scenarios
- Adjust burst value carefully, too small will block normal users
- Check Tengine access log to see rejected requests marked with 503
Summary
Tengine built-in limit_req module is simple and effective basic defense against brute force attacks.
AdSense Slot