Je me suis posé la question aussi...mais ce qui est décrit sur la page Netfilter me semble plus efficace qu'un simple drop :
Connections are accepted, but immediately switched to the persist state (0 byte window), in which the remote side stops sending data and asks to continue every 60-240 seconds.
Attempts to close the connection are ignored, forcing the remote side to time out the connection in 12-24 minutes.
[^] # Re: TARPITS : Ralentir la propagation des vers avec IPtables
Posté par Brunus (Mastodon) . En réponse à la dépêche TARPITS : Ralentir la propagation des vers avec IPtables. Évalué à 9.
Connections are accepted, but immediately switched to the persist state (0 byte window), in which the remote side stops sending data and asks to continue every 60-240 seconds.
Attempts to close the connection are ignored, forcing the remote side to time out the connection in 12-24 minutes.