Reputation-based (and optionally country-based) IP blocklist tool.
- (default) block IP ranges and ASNs with a bad reputation
- (optional) block whole countries
- nftables-based, dropping before ufw / firewalld / fail2ban
- runs on a host, or inline as a transparent bridge (
MODE=bridge) - systemd: auto-load on boot + weekly auto-refresh of lists
- your admin networks (
ADMIN_NETS) and established connections are never blocked
curl -fsSL https://raw.githubusercontent.com/kreonet/republock/main/install.sh | sudo sh -sAlso declare networks that must never be blocked (your office/home/mgmt):
curl -fsSL https://raw.githubusercontent.com/kreonet/republock/main/install.sh \
| sudo sh -s -- --admin-net 111.111.111.0/24 --admin-net 222.222.222.0/24Add --country cn --country ru to turn on geo blocking too (off by default).
sudo republock status # per-group state (enabled/disabled) + list sizes
sudo republock disable cn # unblock a group (list kept)
sudo republock enable cn # re-block a group (refreshes its list first)
sudo republock update # refresh lists now (download + apply)
sudo republock reload # re-apply from cache (config / toggle state)- Default groups:
spammers,abuseipdb,asndrop - Common opt-in countries:
cn(China),ru(Russia),kp(North Korea),ir(Iran)
Geo blocking is off by default. To enable it, set COUNTRIES="cn ru kp ir" in /etc/republock/republock.conf and run sudo republock update.
If you travel to a country you're blocking, your own IP falls into that country's range — so you're already blocked and can't unblock remotely. Disable it before you leave, from somewhere that can still reach the host.
sudo republock disable cn # before departure (cn = example)
# ... trip ...
sudo republock enable cn # after you're backReputation feeds list individual addresses, but abuse clusters. AGGREGATE collapses a block dense with listed addresses into a single prefix — fewer set entries, and the unlisted neighbours are pre-empted.
AGGREGATE[abuseipdb]="26:4" # a /26 holding >= 4 listed addresses -> block the /26On the 30-day AbuseIPDB list that shrinks the set by 29% with zero loss of existing coverage. But ~40% of a sample of the aggregated /26s turned out to be major cloud (Azure, Linode, Cloudflare) or consumer/mobile ISP space — taking unrelated tenants or subscribers with them. Off by default; read the measured numbers and trade-offs in docs/aggregation.md first.
Measured 2026-09-10. Feeds refresh continuously, so these drift.
| Group | Entries | Source |
|---|---|---|
spammers |
29,328 | Spamhaus DROP + FireHOL level1 + blocklist.de (merged, deduped, low false-positive) |
abuseipdb |
81,217 | AbuseIPDB confidence-100% reporters, last 7 days (borestad mirror; 1d–30d window configurable) |
asndrop |
4,469 | Spamhaus ASN-DROP — 434 malicious ASNs expanded to prefixes via ipverse/asn-ip |
| default total | 115,014 | |
cn (opt-in) |
5,513 | ipdeny.com per-country aggregated zones (v4+v6) |
ru (opt-in) |
8,652 | ” |
What asndrop actually blocks, and why country blocking cannot catch it, is in docs/asn-drop.md with measurements.
- Memory: nftables interval sets use the pipapo algorithm — ~0.8 KB per entry (it trades memory for lookup speed). The three default groups, ~115,000 entries ≈ ~90 MB. It scales linearly with entry count, so adding many countries or large lists (FireHOL L2/L3, …) can reach hundreds of MB to GBs. The most effective knob is the
abuseipdbwindow (7d 81,217 → 3d 58,164). - CPU: negligible. Sets are passive (resident in kernel memory), so no ongoing CPU; lookups happen only on new connections (established traffic short-circuits) and are very fast. Refresh is a brief weekly
nftload.
| Document | Contents |
|---|---|
| How it works | nftables table & priority, group toggles, self-lockout guard, requirements, systemd, uninstall |
| Configuration | full republock.conf reference — ADMIN_NETS, COUNTRIES, EXTRA_GROUPS, HOOK (Docker), source overrides |
| Bridge mode | transparent inline filtering — the stateless/symmetric rationale, the bridge-nf-call-iptables trap, netplan & nmcli examples |
| ASN-DROP | blocking malicious ASNs — how it works, measured size, what it blocks, risks |
| Prefix aggregation | AGGREGATE measurements and trade-offs |
Annotated config template: republock.conf.example