Answer the question
In order to leave comments, you need to log in
How to make server access only from Russia in iptables without geoip?
Good time.
I do not consider geoip.
From here , ripe.net parsed all Russian subnet addresses.
If I disable everything in /etc/sysconfig/iptables and only allow this:
-A INPUT -s 2.60.0.0/14,2.92.0.0/14,...62 тыщи подсетей...,213.110.224.0/19,217.71.128.0/20 -j ACCEPT
Answer the question
In order to leave comments, you need to log in
man ipset
otherwise your next question will be - why is everything so slow.
Because every packet goes through 62k checks....
You can run all your traffic through CloudFlare and hope the bad guys don't remember your direct IP.
Then "the whole world" will communicate with the muzzle of CF, which can cut off DDOS and other suspicious activities.
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question