Skip to content

Build1 publisher2 min readPublished

Netban bans an SSH bot's whole /24 in nftables ahead of UFW's allow-22 rule

Netban, a Bash script posted on dev.to, bans an SSH bot's whole /24 for 24 hours by default. Its author built it after one bot tripped Wazuh 91 times. Bans live in a separate nftables table and expire by themselves, leaving existing UFW or firewalld rules untouched.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • A plain ufw deny on the /24 often fails because UFW appends it after the existing allow-22 rule, so the allow matches first unless the operator remembers ufw insert 1.
  • A raw iptables -I rule does block the range, but it stays forever as a DROP rule with no comment, date or owner that nobody dares delete.
  • Durations such as 6h or 2d are accepted, and a perm ban takes a note that netban writes, with the date, to /etc/netban/permanent.list.
  • The author positions netban as a manual fallback beside Wazuh active response, Suricata, fail2ban or CrowdSec, for when those miss something or traffic must stop now.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Because the drop rules name no port, anyone legitimate inside a banned /24 loses every inbound service on the host until the timeout lapses or the ban is lifted.
  • decision Per-IP bans cannot keep up with a bot that rotates addresses, so the operator has to choose a network size up front. Netban's paste-the-alert input makes the /24 the easy default.
  • constraint The tool covers IPv4 networks only. A bot rotating through IPv6 addresses has to be blocked some other way.

UFW and firewalld attach to the input hook at priority 0. Netban's chain attaches at -10. According to the post, that means it runs before them, and a banned range is dropped whatever allow rules sit behind it [13]. The ordering step that `ufw insert 1` needs on every ban is made once, inside the tool [5].

Expiry comes from nftables. Its sets already support a timeout on each element [10]. The author wrote that "netban just wraps that in something you can type at 2am without looking anything up" [11]. A temporary entry in the post's sample listing reads `203.0.113.0/24 timeout 1d expires 23h41m12s` [15].

The chain itself is two lines: `ip saddr @perm counter drop` and `ip saddr @temp counter drop` [14]. Both match on source address alone [2]. Input is forgiving. Host bits are masked, so pasting `203.0.113.239/24` straight from an alert bans 203.0.113.0/24 [8].

The sample `netban -l` output counts 1843 packets dropped by the permanent set and 212 by the temporary one [15]. Each set works out to exactly 60 bytes a packet [1]. These figures are example output from one post. Treat them as a demonstration that the counters work, not as a measurement. The author's summary: "The counters climb, the log goes quiet, and the SIEM stops shouting." [19]

The 91 alerts came from one VM, and every source address sat inside one /24 [1]. Netban fits another host when the same conditions hold. Authentication has to be key-only, so the bot is noise. The author wrote that this one "was trying usernames against a door that doesn't have a keyhole" [18]. Banning it cut SIEM alerts, auth-log growth and CPU spent on rejections [3]. The bot also has to stay inside one range, as this one did [1]. And the 24-hour default depends on the author's observation that most such bots move on after a day or two [17].

I think a manual fallback is the right scope for a tool that drops a whole network with one command. Because temporary bans expire, a mistyped range stays blocked only until its timeout runs out [7]. Everything lives in the inet netban table. The author says removing the tool is one command and cannot break anything else [12].

What to watch

  • An IPv6 version: the tool's own description limits it to IPv4 network bans today.
  • Port-scoped bans as an option, since the current drop rules match source address only.
  • A range that returns after its 24-hour timeout would test the author's day-or-two assumption behind the default.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories