↑ ↓ select, Enter open, Esc close

Create an IP blocklist set in nftables

Caution: This command changes the system. Understand what it does before you run it.

root@server
nft add set inet filter blocklist '{ type ipv4_addr; flags interval; }' && nft insert rule inet filter input ip saddr @blocklist drop

Creates a set named blocklist in the inet filter table that can hold single IPv4 addresses and, thanks to flags interval, also networks like 203.0.113.0/24. The second rule drops all packets whose source is in the set. A set with thousands of entries is much more efficient than the same number of individual rules.

Note: Run this only once, a second call creates a duplicate drop rule. The set and rule are not permanent unless they are in /etc/nftables.conf.

Also searched as

  • nftables create blocklist set
  • block many ips efficiently nftables
  • nft set with interval flag

Related one-liners

All in Firewall

Read first, then run.

The commands on myline.de act directly on servers, files and databases. A wrong path or placeholder can delete data irreversibly or make a server unreachable.

  • All commands are provided without warranty and are not tested on every system.
  • Understand what a command does before running it, and check every placeholder.
  • Make a backup first and, if possible, try it on a test system.
  • You run commands at your own risk. Liability for damages is excluded to the extent permitted by law.