Is IPSum IPv4 only? So basically useless.
Selfhosted
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
-
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
-
No spam posting.
-
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
-
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
-
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
-
No trolling.
Resources:
- selfh.st Newsletter and index of selfhosted software and apps
- awesome-selfhosted software
- awesome-sysadmin resources
- Self-Hosted Podcast from Jupiter Broadcasting
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
ok. I hadn't thought about that.
Are there alternatives? Or is an IPv6 block list not practically possible?
Some thing like this
iptables -I DOCKER-USER -m set --match-set ipsum src -j DROP
Should do what you need
Thank you. I was looking at something like this.
I guess I was asking whether there's a package or project which kinda creates this rule and keeps the ipset list updated.
If I create a rule like that, then next time I'm playing around with this I'm not going to be able to figure out what I've done.
I would have a cron that runs a script to pull the list and update IPset, this might not work.
make a file on your docker server with the below in it, set the file to execute chmod +x file.sh
#!/bin/sh
ipset -q flush ipsum
ipset -q create ipsum hash:ip
for ip in $(curl --compressed https://raw.githubusercontent.com/stamparm/ipsum/master/ipsum.txt 2>/dev/null | grep -v "#" | grep -v -E "\s[1-2]$" | cut -f 1); do ipset add ipsum $ip; done
iptables -D INPUT -m set --match-set ipsum src -j DROP 2>/dev/null
iptables -I INPUT -m set --match-set ipsum src -j DROP
Then add a cron file in /etc/cron.d
that runs the script every 24 hours
10 3 * * * root /root/file.sh
sweet. thanks.
INPUT will need to be DOCKER-USER in your script but otherwise I'll see how it goes.