Skip to content

Instantly share code, notes, and snippets.

@funzoneq
Created February 12, 2013 11:47
Show Gist options
  • Save funzoneq/4761775 to your computer and use it in GitHub Desktop.
Save funzoneq/4761775 to your computer and use it in GitHub Desktop.
Drop al non RIPE ip blocks. Simple trick for DDoS mitigation on dutch-language sites.
/sbin/iptables -A INPUT -s 0.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 1.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 3.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 4.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 6.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 7.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 8.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 9.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 10.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 11.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 12.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 13.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 14.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 15.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 16.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 17.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 18.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 19.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 20.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 21.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 22.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 23.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 24.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 25.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 26.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 27.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 28.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 29.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 30.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 32.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 33.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 34.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 35.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 36.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 38.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 39.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 40.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 41.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 42.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 43.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 44.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 45.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 47.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 48.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 49.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 50.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 51.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 52.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 53.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 54.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 55.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 56.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 57.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 58.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 59.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 60.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 61.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 63.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 64.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 65.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 66.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 67.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 68.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 69.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 70.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 71.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 72.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 73.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 74.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 75.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 76.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 96.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 97.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 98.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 99.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 100.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 101.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 102.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 103.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 104.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 105.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 106.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 107.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 108.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 110.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 111.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 112.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 113.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 114.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 115.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 116.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 117.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 118.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 119.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 120.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 121.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 122.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 123.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 124.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 125.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 126.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 127.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 128.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 129.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 130.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 131.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 132.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 133.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 134.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 135.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 136.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 137.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 138.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 139.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 140.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 142.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 143.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 144.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 146.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 147.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 148.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 149.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 150.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 152.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 153.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 154.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 155.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 156.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 157.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 158.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 159.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 160.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 161.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 162.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 163.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 164.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 165.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 166.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 167.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 168.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 169.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 170.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 171.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 172.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 173.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 174.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 175.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 177.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 179.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 180.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 181.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 182.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 183.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 184.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 186.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 187.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 189.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 190.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 191.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 192.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 196.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 197.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 198.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 199.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 200.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 201.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 202.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 203.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 204.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 205.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 206.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 207.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 208.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 209.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 210.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 211.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 214.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 215.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 216.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 218.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 219.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 220.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 221.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 222.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 223.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 224.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 225.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 226.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 227.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 228.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 229.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 230.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 231.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 232.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 233.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 234.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 235.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 236.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 237.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 238.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 239.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 240.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 241.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 242.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 243.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 244.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 245.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 246.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 247.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 248.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 249.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 250.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 251.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 252.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 253.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 254.0.0.0/8 -j DROP
/sbin/iptables -A INPUT -s 255.0.0.0/8 -j DROP
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment