proxies: block a few more nets

Signed-off-by: Kevin Fenzi <kevin@scrye.com>
This commit is contained in:
Kevin Fenzi
2025-06-28 17:07:23 -07:00
parent da58790976
commit 46e93ae29b

View File

@@ -61,6 +61,8 @@ nft_block_rules:
- 'add rule ip filter INPUT ip saddr 47.235.0.0/16 counter reject'
- 'add rule ip filter INPUT ip saddr 47.240.0.0/14 counter reject'
- 'add rule ip filter INPUT ip saddr 47.244.0.0/15 counter reject'
- 'add rule ip filter INPUT ip saddr 152.53.36.0/24 counter reject'
- 'add rule ip filter INPUT ip saddr 66.249.69.0/24 counter reject'
nft_custom_rules:
# Need for rsync from log01 for logs.
- 'add rule ip filter INPUT ip saddr 10.3.163.39 tcp dport 873 counter accept'