Reverse --exeptions how to #25
Unanswered
lejurassien
asked this question in
Q&A
Replies: 1 comment 1 reply
-
you could add another chain (TOBLERONE or whatever name you like) and put your IP's in there. Just make sure the priority is lower than the one of your country chain.
|
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hello, first of all I would like to thank you for your great work that really facilitates the management of authorized ip on my website it is a big plus thank you!
I have a question after having set up the script then the service as well as crontab, I put you the command line that I use like that it will be more comprehensible,
0 5 * * 1 /usr/sbin/nft-geo-filter --allow --allow-established --interface ens3 --table-family inet --table-name suisse-filter CH --log-drop --log-drop-prefix GEO-NFT --log-drop-level notice
I only allow Swiss CH ip's to be able to connect but I have a range of Swiss ip's that I would still like to block is there a reverse of --exceptions or a way to add this range 146.4.22.128/26 that is Swiss but I don't want to allow to connect?
I hope I've been clear, I don't speak English and everything is translated
Thanks
Beta Was this translation helpful? Give feedback.
All reactions