↑ ↓ select, Enter open, Esc close

Add an IP address to an nftables blocklist

Caution: This command changes the system. Understand what it does before you run it.

Adjust the values, the command updates live
root@server
nft add element inet filter blocklist '{ 203.0.113.25 }'

Adds the address to the previously created blocklist set, and the associated drop rule takes effect immediately. Multiple entries can be specified inside the curly braces, separated by commas. nft list set inet filter blocklist shows the contents, and an entry is removed with nft delete element using the same syntax.

Note: The set only accepts IPv4. IPv6 needs a second set with type ipv6_addr and a rule with ip6 saddr.

Also searched as

  • nftables block ip address
  • nft add element to set
  • add ip to nftables blocklist

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.