Replies: 5 comments 67 replies
-
It is possible with nftables but currently my code doesn't implement this. You can add a feature request and if there will be more people asking for this feature, I'll implement it. In the meanwhile, you could modify the geoip-shell-apply.sh script to block some ports. The code is reasonably well commented, so you should be able to find the relevant lines easily. If you need more specific directions, please describe your use case and what you want to block and allow (open all ports except what's closed? close all ports except what's open? which protocols?) |
Beta Was this translation helpful? Give feedback.
-
I'm getting ipv4 address '98.140.240.90' failed regex validation. I change that ip for security purpose. I want to use only my public address.
|
Beta Was this translation helpful? Give feedback.
-
I'll need output of these 3 commands (the latter 2 present more or less the same information but with slightly different detail):
|
Beta Was this translation helpful? Give feedback.
-
You'll be able to see statistics of traffic hitting each rule, including the whitelist blocking rule and the ACCEPT rules. So in short, yes. To see that, use the If you update, don't forget to re-add your custom rules to the -apply script (now it's line 306). |
Beta Was this translation helpful? Give feedback.
-
@vladosam I wonder if you are still using the project and what your experience with it is. Also you probably have already noticed, but just to make sure: geoip-shell doesn't have separate branches for iptables and nftables anymore. All recent releases support both firewall backends (and I implemented the option to change the backend if you have both nftables and iptables-compat installed). There were a few bugs affecting iptables installs because the code went through substantial changes, now I believe all of them have been ironed out. P.s. I tried to write a post on the selfhosted subreddit but it didn't get approved by the admins, probably because my karma is not good enough xD. |
Beta Was this translation helpful? Give feedback.
-
Hi, is there option to geoblock some ports and leave other ports unblocked?
Beta Was this translation helpful? Give feedback.
All reactions