Skip to content

Repository files navigation

republock

🇺🇸 English · 🇰🇷 한국어

Reputation-based (and optionally country-based) IP blocklist tool.

  • (default) block IP ranges and ASNs with a bad reputation
  • (optional) block whole countries
  • nftables-based, dropping before ufw / firewalld / fail2ban
  • runs on a host, or inline as a transparent bridge (MODE=bridge)
  • systemd: auto-load on boot + weekly auto-refresh of lists
  • your admin networks (ADMIN_NETS) and established connections are never blocked

Install

curl -fsSL https://raw.githubusercontent.com/kreonet/republock/main/install.sh | sudo sh -s

Also declare networks that must never be blocked (your office/home/mgmt):

curl -fsSL https://raw.githubusercontent.com/kreonet/republock/main/install.sh \
  | sudo sh -s -- --admin-net 111.111.111.0/24 --admin-net 222.222.222.0/24

Add --country cn --country ru to turn on geo blocking too (off by default).

Usage

sudo republock status              # per-group state (enabled/disabled) + list sizes
sudo republock disable cn          # unblock a group (list kept)
sudo republock enable  cn          # re-block a group (refreshes its list first)
sudo republock update              # refresh lists now (download + apply)
sudo republock reload              # re-apply from cache (config / toggle state)
  • Default groups: spammers, abuseipdb, asndrop
  • Common opt-in countries: cn (China), ru (Russia), kp (North Korea), ir (Iran)

Geo blocking is off by default. To enable it, set COUNTRIES="cn ru kp ir" in /etc/republock/republock.conf and run sudo republock update.

🧳 Traveling to a country you block (important)

If you travel to a country you're blocking, your own IP falls into that country's range — so you're already blocked and can't unblock remotely. Disable it before you leave, from somewhere that can still reach the host.

sudo republock disable cn      # before departure  (cn = example)
# ... trip ...
sudo republock enable  cn      # after you're back

(advanced) Prefix aggregation

Reputation feeds list individual addresses, but abuse clusters. AGGREGATE collapses a block dense with listed addresses into a single prefix — fewer set entries, and the unlisted neighbours are pre-empted.

AGGREGATE[abuseipdb]="26:4"   # a /26 holding >= 4 listed addresses -> block the /26

On the 30-day AbuseIPDB list that shrinks the set by 29% with zero loss of existing coverage. But ~40% of a sample of the aggregated /26s turned out to be major cloud (Azure, Linode, Cloudflare) or consumer/mobile ISP space — taking unrelated tenants or subscribers with them. Off by default; read the measured numbers and trade-offs in docs/aggregation.md first.

IP lists

Measured 2026-09-10. Feeds refresh continuously, so these drift.

Group Entries Source
spammers 29,328 Spamhaus DROP + FireHOL level1 + blocklist.de (merged, deduped, low false-positive)
abuseipdb 81,217 AbuseIPDB confidence-100% reporters, last 7 days (borestad mirror; 1d–30d window configurable)
asndrop 4,469 Spamhaus ASN-DROP — 434 malicious ASNs expanded to prefixes via ipverse/asn-ip
default total 115,014
cn (opt-in) 5,513 ipdeny.com per-country aggregated zones (v4+v6)
ru (opt-in) 8,652 ”

What asndrop actually blocks, and why country blocking cannot catch it, is in docs/asn-drop.md with measurements.

Resource footprint

  • Memory: nftables interval sets use the pipapo algorithm — ~0.8 KB per entry (it trades memory for lookup speed). The three default groups, ~115,000 entries ≈ ~90 MB. It scales linearly with entry count, so adding many countries or large lists (FireHOL L2/L3, …) can reach hundreds of MB to GBs. The most effective knob is the abuseipdb window (7d 81,217 → 3d 58,164).
  • CPU: negligible. Sets are passive (resident in kernel memory), so no ongoing CPU; lookups happen only on new connections (established traffic short-circuits) and are very fast. Refresh is a brief weekly nft load.

Reference

Document Contents
How it works nftables table & priority, group toggles, self-lockout guard, requirements, systemd, uninstall
Configuration full republock.conf reference — ADMIN_NETS, COUNTRIES, EXTRA_GROUPS, HOOK (Docker), source overrides
Bridge mode transparent inline filtering — the stateless/symmetric rationale, the bridge-nf-call-iptables trap, netplan & nmcli examples
ASN-DROP blocking malicious ASNs — how it works, measured size, what it blocks, risks
Prefix aggregation AGGREGATE measurements and trade-offs

Annotated config template: republock.conf.example

License

MIT

About

nftables-based country, spammer IP blocklist tool

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages