<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	
	>
<channel>
	<title>
	Comments on: Block all traffic from a Geo-located country with UFW firewall on Ubuntu	</title>
	<atom:link href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/</link>
	<description>I never finish anyth</description>
	<lastBuildDate>Mon, 02 Mar 2026 18:40:54 +0000</lastBuildDate>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
		<item>
		<title>
		By: Andre		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-634</link>

		<dc:creator><![CDATA[Andre]]></dc:creator>
		<pubDate>Mon, 02 Mar 2026 18:40:54 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-634</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-627&quot;&gt;Maroochy&lt;/a&gt;.

Thank you!]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-627" data-wpel-link="internal">Maroochy</a>.</p>
<p>Thank you!</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Maroochy		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-628</link>

		<dc:creator><![CDATA[Maroochy]]></dc:creator>
		<pubDate>Wed, 25 Feb 2026 01:32:27 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-628</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-17&quot;&gt;Alberto Pérez Vázquez&lt;/a&gt;.

Your information is very good. I have used it to block the entire Brazilian country. Pesty B..ds. I would like to point out with UFW you MUST use the &quot;insert 1&quot; rule otherwise the block does not work.

For example when you do a ufw deny from xxx.xxx.xxx.xxx it will place that AFTER your ALLOW rules which means the IP blocked can get through because of the allow rules above.

You must use the following with UFW to make sure the BLOCK/DENY is ABOVE allow rules like so.

ufw insert 1 deny from xxx.xxx.xxx.xxx

The above places the blocked I{ above your allow rules.

I hope this is of use.

Great work. The pesty Brazilians are gone from my 3 servers.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-17" data-wpel-link="internal">Alberto Pérez Vázquez</a>.</p>
<p>Your information is very good. I have used it to block the entire Brazilian country. Pesty B..ds. I would like to point out with UFW you MUST use the "insert 1" rule otherwise the block does not work.</p>
<p>For example when you do a ufw deny from xxx.xxx.xxx.xxx it will place that AFTER your ALLOW rules which means the IP blocked can get through because of the allow rules above.</p>
<p>You must use the following with UFW to make sure the BLOCK/DENY is ABOVE allow rules like so.</p>
<p>ufw insert 1 deny from xxx.xxx.xxx.xxx</p>
<p>The above places the blocked I{ above your allow rules.</p>
<p>I hope this is of use.</p>
<p>Great work. The pesty Brazilians are gone from my 3 servers.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Maroochy		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-627</link>

		<dc:creator><![CDATA[Maroochy]]></dc:creator>
		<pubDate>Wed, 25 Feb 2026 01:28:13 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-627</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-17&quot;&gt;Alberto Pérez Vázquez&lt;/a&gt;.

Your information is very good. I have used it to clock the entire Brazilian country. Besty B..ds. I would like to point out with ufw you MUST use the  insert 1 rule otherwise the block does not work.

For example when you do a ufw deny from xxx.xxx.xxx.xxx it will place that AFTER your ALLOW rules which means the I{ blocked can get through.

You must use the following with UFW to make sure the BLOCK/DENY is ABOVE allow ruleds like so.

ufw insert 1 deny from xxx.xxx.xxx.xxx

I hope this is of use.

Great work. The pesty Brazilians are gone from my 3 servers.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-17" data-wpel-link="internal">Alberto Pérez Vázquez</a>.</p>
<p>Your information is very good. I have used it to clock the entire Brazilian country. Besty B..ds. I would like to point out with ufw you MUST use the  insert 1 rule otherwise the block does not work.</p>
<p>For example when you do a ufw deny from xxx.xxx.xxx.xxx it will place that AFTER your ALLOW rules which means the I{ blocked can get through.</p>
<p>You must use the following with UFW to make sure the BLOCK/DENY is ABOVE allow ruleds like so.</p>
<p>ufw insert 1 deny from xxx.xxx.xxx.xxx</p>
<p>I hope this is of use.</p>
<p>Great work. The pesty Brazilians are gone from my 3 servers.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-33</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Mon, 29 Jan 2024 12:32:25 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-33</guid>

					<description><![CDATA[Thank you :).]]></description>
			<content:encoded><![CDATA[<p>Thank you :).</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-32</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Sun, 28 Jan 2024 12:20:22 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-32</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-31&quot;&gt;Danny Regalia&lt;/a&gt;.

That&#039;s not very surprising to me that both UFW and fail2ban are having issues because the ones with 4 numbers are in fact not ip4 IP addresses. I have no idea what they actually are.  WHen I do a whois on one of those addresses it doesn&#039;t understand the address either.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-31" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>That's not very surprising to me that both UFW and fail2ban are having issues because the ones with 4 numbers are in fact not ip4 IP addresses. I have no idea what they actually are.  WHen I do a whois on one of those addresses it doesn't understand the address either.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-31</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Sun, 28 Jan 2024 12:07:32 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-31</guid>

					<description><![CDATA[I lost your email that you just reply to me about the image that I sent you.  Like I was saying, both UFW and Fail2ban goes crazy when I try and ban those ip address with the 4 digits in them.  Speaking of IP address.  I sent you another email today about another problem, but in the same cat.  I found another source of ip address that I would like to use &lt;a href=&quot;#&quot; rel=&quot;nofollow ugc&quot;&gt;https://github.com/stamparm/ipsum&lt;/a&gt;.  Problem with using his method is that for some odd reason UFW will disappear from me.  His files don&#039;t have the CIDR format.  How can I use your write method on his files and load them in?]]></description>
			<content:encoded><![CDATA[<p>I lost your email that you just reply to me about the image that I sent you.  Like I was saying, both UFW and Fail2ban goes crazy when I try and ban those ip address with the 4 digits in them.  Speaking of IP address.  I sent you another email today about another problem, but in the same cat.  I found another source of ip address that I would like to use <a href="#" rel="nofollow ugc">https://github.com/stamparm/ipsum</a>.  Problem with using his method is that for some odd reason UFW will disappear from me.  His files don't have the CIDR format.  How can I use your write method on his files and load them in?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-30</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Sun, 28 Jan 2024 11:55:45 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-30</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-29&quot;&gt;Danny Regalia&lt;/a&gt;.

That&#039;s  a mysterious list of numbers. I have never before saw such numbers in any webserver log files. This is a complete mystery to me what these are. Very strange..]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-29" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>That's  a mysterious list of numbers. I have never before saw such numbers in any webserver log files. This is a complete mystery to me what these are. Very strange..</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-29</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Sat, 27 Jan 2024 07:43:55 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-29</guid>

					<description><![CDATA[I have that file.  Attached is the file I hope you can give me some answers because everyone I&#039;ve asked doesn&#039;t have a clue. https://uploads.disquscdn.com/images/33af7ba7bca6843f9e43402a54cdc26de6f8ecc5e4c78d7dde07d0759a72d0cd.png]]></description>
			<content:encoded><![CDATA[<p>I have that file.  Attached is the file I hope you can give me some answers because everyone I've asked doesn't have a clue. https://uploads.disquscdn.com/images/33af7ba7bca6843f9e43402a54cdc26de6f8ecc5e4c78d7dde07d0759a72d0cd.png</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-28</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 22:09:08 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-28</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-27&quot;&gt;ustoopia&lt;/a&gt;.

As soon as I find that ip address, I&#039;ll send you (don&#039;t know how) a picture of it.  I come to find out that iptables is depreciated, and being replaced with nftables.  If that&#039;s the case, what&#039;s going to be ufw frontend?  Iptables still or move over to nftables?  I love the ideal of forming a text list and having it stored that way instead of watching &quot;Rule Added&quot; for about 6 hours.  No thank you, however, I did noticed something today while I was doing it.  I had HTOP running in the back ground.  I noticed that the program would pick up the IP address for ufw, deposit it into the folder of iptables, and then reload ufw again.  That is why it&#039;s taking so long.  Yes, I&#039;m still confused about which way to go with this, as I would hate for a year to go by, and then they kill iptables.  But I don&#039;t see that happing because ufw uses iptables.  Your thoughts about this?]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-27" data-wpel-link="internal">ustoopia</a>.</p>
<p>As soon as I find that ip address, I'll send you (don't know how) a picture of it.  I come to find out that iptables is depreciated, and being replaced with nftables.  If that's the case, what's going to be ufw frontend?  Iptables still or move over to nftables?  I love the ideal of forming a text list and having it stored that way instead of watching "Rule Added" for about 6 hours.  No thank you, however, I did noticed something today while I was doing it.  I had HTOP running in the back ground.  I noticed that the program would pick up the IP address for ufw, deposit it into the folder of iptables, and then reload ufw again.  That is why it's taking so long.  Yes, I'm still confused about which way to go with this, as I would hate for a year to go by, and then they kill iptables.  But I don't see that happing because ufw uses iptables.  Your thoughts about this?</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-27</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 21:14:38 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-27</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-26&quot;&gt;Danny Regalia&lt;/a&gt;.

The four numbers was not a typo? Well then I think you are looking at an ipv6 address. A screenshot would perhaps explain things better. 

What you can try is do:  sudo mkdir /etc/iptables/  and then try again to write the file /etc/iptables/rules.iptables

Maybe the github page here https://github.com/poddmo/ufw-blocklist  can be helpful to you. The developer created that repository to make the process even easier.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-26" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>The four numbers was not a typo? Well then I think you are looking at an ipv6 address. A screenshot would perhaps explain things better. </p>
<p>What you can try is do:  sudo mkdir /etc/iptables/  and then try again to write the file /etc/iptables/rules.iptables</p>
<p>Maybe the github page here https://github.com/poddmo/ufw-blocklist  can be helpful to you. The developer created that repository to make the process even easier.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-26</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 17:51:21 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-26</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-24&quot;&gt;ustoopia&lt;/a&gt;.

Really that is the ip address that I found in my access log.  Of course I made it up (the ip address part), but the part that has 4 numbers in it, isn&#039;t made up.  I have seen in the past year a large numbere of ip address that has 4 numbers in it.  Sorry if I mislead you on that one.
Since I have you on the message, may I ask another question if you don&#039;t mind.  Today I merge 4 countries of ip&#039;s address together.  Wow 345,392 of them.  Tonight as I was getting tried of watching Rules Added, I decided to stop it.  Even tho it was saved, but that took 6 hours and according to everything I have to do the 345,392 ip address would of taken at least a week to do.  So I decided to try the &quot;https://blog.ip2location.com/knowledge-base/how-to-block-ip-addresses-from-a-country-using-ipset/&quot; the ipset route instead.  That was much, much quicker.  However, I came to a road block that maybe you can help me out with.  If you go to the direction page the road block happen on Step #10.  I figured out how to ipset save &#062; /etc/countryblocker.ipset.  That worked.  But the following line #2.  iptables-save &#062; /etc/iptables/rules.iptables didn&#039;t work.  Everytime I ran it I got the error bash:  /etc/iptables/rules.iptables:  No such file or directory.  What gives, and how do I correct it.  Last question.  So if I decided to go with this &quot;ipset&quot; thing, how am i support to add more?
Thanks a millions on this one.
Dan]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-24" data-wpel-link="internal">ustoopia</a>.</p>
<p>Really that is the ip address that I found in my access log.  Of course I made it up (the ip address part), but the part that has 4 numbers in it, isn't made up.  I have seen in the past year a large numbere of ip address that has 4 numbers in it.  Sorry if I mislead you on that one.<br />
Since I have you on the message, may I ask another question if you don't mind.  Today I merge 4 countries of ip's address together.  Wow 345,392 of them.  Tonight as I was getting tried of watching Rules Added, I decided to stop it.  Even tho it was saved, but that took 6 hours and according to everything I have to do the 345,392 ip address would of taken at least a week to do.  So I decided to try the "https://blog.ip2location.com/knowledge-base/how-to-block-ip-addresses-from-a-country-using-ipset/" the ipset route instead.  That was much, much quicker.  However, I came to a road block that maybe you can help me out with.  If you go to the direction page the road block happen on Step #10.  I figured out how to ipset save &gt; /etc/countryblocker.ipset.  That worked.  But the following line #2.  iptables-save &gt; /etc/iptables/rules.iptables didn't work.  Everytime I ran it I got the error bash:  /etc/iptables/rules.iptables:  No such file or directory.  What gives, and how do I correct it.  Last question.  So if I decided to go with this "ipset" thing, how am i support to add more?<br />
Thanks a millions on this one.<br />
Dan</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-25</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 15:13:06 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-25</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-23&quot;&gt;Danny Regalia&lt;/a&gt;.

I&#039;m not entirely sure what you are asking exactly. But let me say that you can add as many sets if IP&#039;s to ban after having imported China. It shouldn&#039;t impact any of the things you imported before. China is the biggest one and therefore takes the longest to complete. I can imagine that a raspberry pi will take its time for these actions. Any other country you decide to add won&#039;t take as long as it did for China.  Not sure if I answered your question with this. Let me know plz.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-23" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>I'm not entirely sure what you are asking exactly. But let me say that you can add as many sets if IP's to ban after having imported China. It shouldn't impact any of the things you imported before. China is the biggest one and therefore takes the longest to complete. I can imagine that a raspberry pi will take its time for these actions. Any other country you decide to add won't take as long as it did for China.  Not sure if I answered your question with this. Let me know plz.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-24</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Fri, 26 Jan 2024 15:06:40 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-24</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-22&quot;&gt;Danny Regalia&lt;/a&gt;.

The address you mention can by definition not be a valid IP address. 192.30.3404.293 where 3404 simply isn&#039;t possible due to how the technology behind it all works. I&#039;m guessing you made a typo error??
My first guess would be that this is part of a local area network range because it begins with 192. Not sure about that though. I&#039;ve never heard of 192.30. Until just now. If you tell me that correct address, then we can do a bit more investigating.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-22" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>The address you mention can by definition not be a valid IP address. 192.30.3404.293 where 3404 simply isn't possible due to how the technology behind it all works. I'm guessing you made a typo error??<br />
My first guess would be that this is part of a local area network range because it begins with 192. Not sure about that though. I've never heard of 192.30. Until just now. If you tell me that correct address, then we can do a bit more investigating.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-23</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 21:04:44 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-23</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-20&quot;&gt;ustoopia&lt;/a&gt;.

Alberto - using the information on this page, as I like the way I can do it,  if I wanted to add another set of ip&#039;s to ban, how would I go about doing it without deleing the set from China that I already have?  Again, I&#039;m new to this stuff and I want to make sure before I see another 2.5 hours go down the drain.  I&#039;m doing this on a raspberry pi verison 4.  Loading in the China file, it did in fact take about 2.5 hours before I could check it out.  After that my webserver seems to be find as far as performanace goes I didn&#039;t see any slow downs at all.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-20" data-wpel-link="internal">ustoopia</a>.</p>
<p>Alberto - using the information on this page, as I like the way I can do it,  if I wanted to add another set of ip's to ban, how would I go about doing it without deleing the set from China that I already have?  Again, I'm new to this stuff and I want to make sure before I see another 2.5 hours go down the drain.  I'm doing this on a raspberry pi verison 4.  Loading in the China file, it did in fact take about 2.5 hours before I could check it out.  After that my webserver seems to be find as far as performanace goes I didn't see any slow downs at all.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-22</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 17:02:28 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-22</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-19&quot;&gt;ustoopia&lt;/a&gt;.

Sorry this is a P.S.  This is to show you how NEW I am to this stuff.  I just started a website (currently down), and I&#039;ve noticed alot of traffic in my access.log.  So I installed UFW and Fail2ban and to my eyes, I&#039;m still getting alot.  Then I noticed your post (old post) and I said &quot;wow&quot;, I have access to the world to ban.  Actually, I would love to ban all IP address looking at my site, except those people (IP Address) that currently live in a 50 mile distances from my house.  The post that I used was very simple and not confusing at all.  Which leave me to ask this one question.  Sometimes I see a log entry in my access log from an IP address of 192.30.3404.293.  This is NOT  a normal IP address because I can&#039;t ban it using UFW or Fail2ban.  By any chance do you know what type of IP address this is?
Thanks
Dan]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-19" data-wpel-link="internal">ustoopia</a>.</p>
<p>Sorry this is a P.S.  This is to show you how NEW I am to this stuff.  I just started a website (currently down), and I've noticed alot of traffic in my access.log.  So I installed UFW and Fail2ban and to my eyes, I'm still getting alot.  Then I noticed your post (old post) and I said "wow", I have access to the world to ban.  Actually, I would love to ban all IP address looking at my site, except those people (IP Address) that currently live in a 50 mile distances from my house.  The post that I used was very simple and not confusing at all.  Which leave me to ask this one question.  Sometimes I see a log entry in my access log from an IP address of 192.30.3404.293.  This is NOT  a normal IP address because I can't ban it using UFW or Fail2ban.  By any chance do you know what type of IP address this is?<br />
Thanks<br />
Dan</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: Danny Regalia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-21</link>

		<dc:creator><![CDATA[Danny Regalia]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 16:51:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-21</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-19&quot;&gt;ustoopia&lt;/a&gt;.

I missed that part.  Besides, I think the first one has MORE info like the port 22 stuff as I&#039;m very new to Linux.  Great job tho.]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-19" data-wpel-link="internal">ustoopia</a>.</p>
<p>I missed that part.  Besides, I think the first one has MORE info like the port 22 stuff as I'm very new to Linux.  Great job tho.</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-20</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 09:21:55 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-20</guid>

					<description><![CDATA[I&#039;m so sorry that I&#039;m just now noticing this comment because of a different comments somebody posted here. 

It does indeed list all the IP&#039;s when you do ufw status. That is actually for me personally, one of the downsides of using this technique. It does not however noticeably impact the performance of the server. A different way to geo block is by using Cloudflared. A free account will be sufficient for this. Cloudflared allows you to create rule sets. Simply create an awf rule that does something like: if request comes from such and such country, block it.
Also, the newer, updated post on this subject contains a link to a github page that greatly simplifies doing this. At the bottom of this page: https://www.ustoopia.nl/technical/tips-and-tricks/block-countries-based-on-geo-data-with-ufw-firewall/]]></description>
			<content:encoded><![CDATA[<p>I'm so sorry that I'm just now noticing this comment because of a different comments somebody posted here. </p>
<p>It does indeed list all the IP's when you do ufw status. That is actually for me personally, one of the downsides of using this technique. It does not however noticeably impact the performance of the server. A different way to geo block is by using Cloudflared. A free account will be sufficient for this. Cloudflared allows you to create rule sets. Simply create an awf rule that does something like: if request comes from such and such country, block it.<br />
Also, the newer, updated post on this subject contains a link to a github page that greatly simplifies doing this. At the bottom of this page: https://www.ustoopia.nl/technical/tips-and-tricks/block-countries-based-on-geo-data-with-ufw-firewall/</p>
]]></content:encoded>
		
			</item>
		<item>
		<title>
		By: ustoopia		</title>
		<link>https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-19</link>

		<dc:creator><![CDATA[ustoopia]]></dc:creator>
		<pubDate>Thu, 25 Jan 2024 09:04:20 +0000</pubDate>
		<guid isPermaLink="false">https://www.ustoopia.nl/?p=3545#comment-19</guid>

					<description><![CDATA[In reply to &lt;a href=&quot;https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-18&quot;&gt;Danny Regalia&lt;/a&gt;.

Just let it run. But I&#039;m curious why you followed the old tutorial. At the top of the page is clearly stated that a newer updated version can be found here: https://www.ustoopia.nl/technical/tips-and-tricks/block-countries-based-on-geo-data-with-ufw-firewall/]]></description>
			<content:encoded><![CDATA[<p>In reply to <a href="https://www.ustoopia.nl/technical/block-all-traffic-from-a-geo-located-country-with-ufw-firewall-on-ubuntu/#comment-18" data-wpel-link="internal">Danny Regalia</a>.</p>
<p>Just let it run. But I'm curious why you followed the old tutorial. At the top of the page is clearly stated that a newer updated version can be found here: https://www.ustoopia.nl/technical/tips-and-tricks/block-countries-based-on-geo-data-with-ufw-firewall/</p>
]]></content:encoded>
		
			</item>
	</channel>
</rss>
