Alan Orth
9bba0d96bb
I will try using nftables directly instead of via firewalld as of Debian 11 as it is the replacement for the iptables/ipset stack in recent years and is easier to work with. This also includes a systemd service, timer, and script to update the spamhaus DROP lists as nftables sets. Still need to add fail2ban support.
6 lines
72 B
Plaintext
6 lines
72 B
Plaintext
#!/usr/sbin/nft -f
|
|
|
|
define SPAMHAUS_IPV6 = {
|
|
fd21:3523:74e0:7301::/64
|
|
}
|