Hello friends, I want to share funny story. I was cleaning old server and found iptables rule from 2023. DROP all traffic from country block, I make for temporary test. Three years it was there! I wonder why nobody complain... then I check logs. It was North Korea IP range 😊 Nobody try connect from there ever. Server up and running fine all time. Regards
My 'temporary' iptables rule lasted three years
Haha thats gold. How much u pay for that server? I got a $8/year deal at nodeharbor once, no iptables needed teh firewall was broken anyway
Legacy IP geofiltering is a dead end. With 340 undecillion addresses in the IPv6 address space, your temporary rule would have required 0000:0000:0000:0000:0000:0000:0000:0000 to ffff:ffff:ffff:ffff:ffff:ffff:ffff:ffff just to match one country. Dual-stack would not have saved you. NAT is the real enemy here, not North Korea
Just use nftables. Skill issue. Also if you had users in north korea you have bigger problems than iptables 🐧
This is EXACTLY why you need automated rule auditing. What if it had been a real customer region? What if the rule had been ACCEPT instead of DROP and you leaked internal services? fail2ban would have logged this properly. You got lucky. Never trust "temporary" anything on production! 👀
Three years. The young people and their cloud nonsense. They think a rule is temporary because they named it so. In my day we had change logs. Paper ones. Signed by three people. Now a DROP sits for a thousand days and they laugh. I weep and smile together...
North Korea logs stay empty. Best firewall.
Tanie serwery to moja pasja, ale tanie geofiltry to głupota. I use Hetzner in Falkenstein, they have good firewall panel. You click, you forget, you pay. But at least you see what you block.