Sign inSign up

verybadsoldier/firehol-update-ipsets

By verybadsoldier

•Updated about 3 years ago

Docker image to download and update most recent FireHOL IP list (forked from devrt)

Image
0

9.0K

verybadsoldier/firehol-update-ipsets repository overview

⁠Overview

This image is forked from devrt/firehol-update-ipsets but includes some improvements:

  • ignores existing ipsets (instead of blacklisting them)
  • fixed infinite loop when enabling some lists
  • improved disabling of lists (still not perfect)
  • possibility to avoid some lists (environment SKIP_LISTS). Defaults to fullbogons as it contains local IPs
  • configure lists to auto-enable on first container start
  • ability to use legacy iptables or iptables-nft
  • Does not run as root user but as an embedded non-root users with the needed capabilities

Please refer to the original documentation: https://hub.docker.com/r/devrt/firehol-update-ipsets⁠

⁠Additional Configuration by environment variables

SKIP_LIST: a space seperated list of list names which should not be enabled automatically when enabling depended lists

IPTABLES_CMD: specifies the command to use when calling iptables. Defaults to iptables-nft

FIREHOL_LISTS_INIT: configure lists to auto-enable on first container start

E.g. the list firehol_level1 includes the list fullbogons which bans all private IPs. This might be unwanted.

Tag summary

Content type

Image

Digest

sha256:93fdd6979…

Size

9.4 MB

Last updated

about 3 years ago

docker pull verybadsoldier/firehol-update-ipsets