Notices where this attachment appears
-
@lewdthewides https://ipset.netfilter.org/
http://www.ipdeny.com/ipblocks/data/countries/cn.zone
-
@p @sjw @i @admin @not_br549 @parker @graf @john_rando @verita84 @Moon Is it?
https://ipset.netfilter.org/
>IP sets are a framework inside the Linux kernel, which can be administered by the ipset utility. Depending on the type, an IP set may store IP addresses, networks, (TCP/UDP) port numbers, MAC addresses, interface names or combinations of them in a way, which ensures lightning speed when matching an entry against a set.
Sure, when you're just blocking a bunch of addresses/subnets, you might get away with creating separate rules for them, but when the count is in thousands, I think it's better to make a single match-all rule.