imthenachoman / How-To-Secure-A-Linux-Server

An evolving how-to guide for securing a Linux server.
Creative Commons Attribution Share Alike 4.0 International
17.56k stars 1.12k forks source link

UFW automatic blacklist rules #109

Closed moltenbit closed 1 year ago

moltenbit commented 1 year ago

Implemented automatic download of blacklist from IPSum and automatic import of rules with UFW.

imthenachoman commented 1 year ago

Why close this? You don't want me to merge it? It looks nice!

moltenbit commented 1 year ago

Why close this? You don't want me to merge it? It looks nice!

I've noticed adding rules this way is extremely slow. We could either limit the number of blocked IPs (IPsum has prepared lists with levels, on how many blacklists an IP appears and we could use a high level) or I could prepare a PR with ipset, which I have implemented on my server after noticing the slowness.