Sign inSign up

thib3113/unifi-blockips-srv

By thib3113

•Updated 4 months ago

Image
0

10K+

thib3113/unifi-blockips-srv repository overview

⁠unifi-blockips-srv

Docker Pulls

⁠TAGS

They work like this :

  • latest : the latest version out
  • sha-<sha> : a precise build for a precise commit, <sha> will be the short sha of the commit
  • 1 : the latest version with major 1 (eg. 1.*.*)
  • 1.1 : the latest version with major 1 and minor 1 (eg. 1.1.*)
  • 1.1.1 : the latest version with major 1, minor 1 and patch 1 (eg. 1.1.1*)

⁠ENV

keydescriptionmandatory
UNIFI_CONTROLLER_IPthe ip of the controller ( or fqdn )yes
UNIFI_CONTROLLER_PORTport of the controller sometimes 8443 or 443yes
UNIFI_USERNAMEusername of a user ( rights levels not tested )yes
UNIFI_PASSWORDpassword of the useryes
UNIFI_SITE_NAMEname of the "site"no (default to first one)
UNIFI_FW_RULE_NAMEname of the FW Ruleyes
UNIFI_FW_RULE_NAME_V6name of the FW Rule for ipv6yes
UNIFI_GROUP_NAMEgroup where the ips will be managedyes
UNIFI_GROUP_NAME_V6group where the ips will be managed for ipv6yes
ADD_CHECKSUMsha256 of the token to add ipno ( but recommended )
RM_CHECKSUMsha256 of the token to add ipno (default to ADD_CHECKSUM, recommended)
portthe port where the app will listenno (default to 3000)

⁠How to use

To add an IP to the blocklist : POST /?token=tatayoyo&ips[]=127.0.0.1

to delete an IP DELETE /?token=tatayoyo2&ips[]=127.0.0.1

token will be check again ADD_CHECKSUM or RM_CHECKSUM . You can use this site to generate your checksum : https://emn178.github.io/online-tools/sha256.html⁠

To secure data in the container, you can pass ENV via /app/.env ( respecting .env format ) .

⁠How to block the Ips

You can see this : https://github.com/tusc/blockips-unifi#preparation⁠ You can reuse the firewall part, create the rule, create the group .

In this script, UNIFI_FW_RULE_NAME will be Scheduled Block Group and UNIFI_GROUP_NAME will be Block_Group

⁠How to run the app

⁠Docker

the image is built automatically for linux/amd64,linux/arm64 and linux/arm/v7 (so in theory compatible with raspberry pi and other arm IoT)

docker run thib3113/unifi-blockips-srv

or with docker compose / swarm:

⁠compose
version: '3.7'
services:
  unifi-blocker:
    image: thib3113/unifi-blockips-srv:latest
    environment:
      PORT: 3000
      UNIFI_CONTROLLER_URL: http://unifi
      UNIFI_SITE_NAME: my_site
      UNIFI_FW_RULE_NAME: my_block_rule
      UNIFI_GROUP_NAME: my_group
      ADD_CHECKSUM: 2c26b46b68ffc68ff99b453c1d30413413422d706483bfa0f98a5e886266e7ae
      RM_CHECKSUM: fcde2b2edba56bf408601fb721fe9b5c338d10ee429ea04fae5511b68fbf8fb9
      # please never set the username / password like that, bind a file to /.env with the variables
      UNIFI_USERNAME: username
      UNIFI_PASSWORD: superPassword
⁠swarm
version: '3.7'
services:
  unifi-blocker:
    image: thib3113/unifi-blockips-srv:latest
    secrets:
      - source: UNIFI_BLOCKER_ENV
        target: /app/.env
    environment:
      PORT: 3000

⁠Configurations for EDR⁠

⁠Crowdsec

#!/bin/bash

IP=$2
DURATION=$3
REASON=$4
JSON_OBJECT=$5

#change this URL by the url to access this script
URL=http://unifi-blocker-ip:3000

#change tokens in the urls

LOG=/var/log/bouncer.log

case $1 in
  add)
    #here the code for the add command
    #echo add ${IP} for ${DURATION}s because "${REASON}" json : ${JSON} >> ${LOG}
    /usr/bin/curl -k --location --request POST "${URL}?token=amldfksqmldk&ips=${IP}"
  ;;
  del)
    #here the code for the del command
    #echo del ${IP} for ${DURATION}s because "${REASON}" json : ${JSON} >> ${LOG}
    /usr/bin/curl -k --silent --location --request DELETE "${URL}?token=qsdazekrlsfdlm&ips=${IP}"
  ;;
  *) echo "unknown action $1" >> ${LOG}
     exit 1;;
esac

⁠fail2ban

/etc/fail2ban/action.d/unifi-ban.conf :

[Definition]
actionstart =
actionstop =
actioncheck =
actionban = /usr/bin/curl -k -v --location --request POST 'http://unifi-blocker-ip:3000?token=amldfksqmldk&ips=<ip>'
actionunban = /usr/bin/curl -k -v --silent --location --request DELETE 'http://unifi-blocker-ip:3000?token=qsdazekrlsfdlm&ips=<ip>'

/etc/fail2ban/jail.d/your-jail.local :

[your-jail]
banaction = unifi-ban

Tag summary

Content type

Image

Digest

sha256:8094bad2a…

Size

62.7 MB

Last updated

4 months ago

docker pull thib3113/unifi-blockips-srv