Create an IP blocklist set in nftables
nftables create blocklist set | block many ips efficiently nftables | nft set with interval flag | nftables | nft | ban | firewallCaution: This command changes the system. Understand what it does before you run it.
nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }' && nft insert rule inet filter input ip saddr @blocklist dropCreates a set named blocklist in the inet filter table that can hold single IPv4 addresses and, thanks to flags interval, also networks like 203.0.113.0/24. The second rule drops all packets whose source is in the set. A set with thousands of entries is much more efficient than the same number of individual rules.
Note: Run this only once, a second call creates a duplicate drop rule. The set and rule are not permanent unless they are in /etc/nftables.conf.
Also searched as
- nftables create blocklist set
- block many ips efficiently nftables
- nft set with interval flag