IPS

Blocklists for iptables / ipset

Classic Linux firewall setup: load the addresses into an ipset and drop matching traffic.

28compatible lists
1supported formats
10categories

Adding a blocklist to iptables / ipset

ipset create blocklist hash:net -exist
curl -fsSL "https://www.team-cymru.org/Services/Bogons/fullbogons-ipv6.txt" | grep -Eo '^[0-9]{1,3}(.[0-9]{1,3}){3}(/[0-9]{1,2})?' | 
  while read -r net; do ipset add blocklist "$net" -exist; done
iptables -I INPUT  -m set --match-set blocklist src -j DROP
iptables -I FORWARD -m set --match-set blocklist src -j DROP

Persist the set and re-run the download from cron to keep it current:

ipset save blocklist -f /etc/ipset.blocklist
# /etc/cron.daily/blocklist

The address shown above is an example. Every list in the directory has its own URL, which you can copy with one click.

By topic

All 28 lists for iptables / ipset

Submit a list
28 lists < 7 days < 30 days older

Filter list from the public FilterLists directory. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.

Comprehensive IP / CIDR
13 entries
±0 last change
updated
FHIPSMTWRTOPN+3

Filter list from the public FilterLists directory. Format: CIDRs (IPv4). See the project homepage for details and inclusion criteria.

Comprehensive IP / CIDR
3,043 entries
+3 -1 last change
updated
FHIPSMTWRTOPN+3

Filter list from the public FilterLists directory. Format: CIDRs (IPv6). See the project homepage for details and inclusion criteria.

Comprehensive IP / CIDR
157.0k entries
+8 -2 last change
updated
FHIPSMTWRTOPN+3
Page 2 of 2
Scroll to Top