Angriffsabwehr9 min read6 sections

In your firewall: block reported attackers

Block the Attack Defense list directly on routers and border firewalls without fail2ban - iptables, nftables, ufw, pf (BSD) and Windows Firewall, synced every 5 minutes.

01

How firewall blocking works

No fail2ban needed on the firewall itself. The block list is a plain-text export - one IP per line, only soft- and hard-listed attackers:

https://reports.provider.tools/api/v1/abuse/export                (all services)
https://reports.provider.tools/api/v1/abuse/export?service=ssh    (single service)

You fetch this list on a schedule (every 5 minutes, like our own sync) and load it into your firewall rule set. Delisted IPs are simply no longer in the list - just rebuild the set each run.

Whitelist first: always exclude your own IPs (office, VPN, monitoring) so you never lock yourself out.

02

iptables + ipset (Linux)

Save as /usr/local/sbin/pt-block-sync.sh, then chmod +x:

#!/usr/bin/env bash
set -e
IPLIST=$(mktemp)
curl -fsS https://reports.provider.tools/api/v1/abuse/export -o "$IPLIST"

ipset destroy provider-tools-block 2>/dev/null || true
ipset create provider-tools-block hash:ip hashsize 4096 maxelem 65536

while read -r ip; do
  [ -n "$ip" ] && ipset add provider-tools-block "$ip" 2>/dev/null || true
done < "$IPLIST"

# Chain anlegen (einmalig) und Regel erzwingen
iptables -N PROVIDER_TOOLS_BLOCK 2>/dev/null || true
iptables -C INPUT -j PROVIDER_TOOLS_BLOCK 2>/dev/null || iptables -I INPUT -j PROVIDER_TOOLS_BLOCK
iptables -F PROVIDER_TOOLS_BLOCK

# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen:
# iptables -A PROVIDER_TOOLS_BLOCK -s 203.0.113.0/24 -j RETURN

iptables -A PROVIDER_TOOLS_BLOCK -m set --match-set provider-tools-block src -j DROP

rm -f "$IPLIST"

Cron (every 5 minutes, matching the network sync):

*/5 * * * * root /usr/local/sbin/pt-block-sync.sh
03

nftables (Linux)

Save as /usr/local/sbin/pt-block-sync-nft.sh, then chmod +x:

#!/usr/bin/env bash
set -e
nft flush set inet filter provider_tools_block 2>/dev/null ||   nft add set inet filter provider_tools_block '{ type ipv4_addr; flags interval; }'
nft add chain inet filter provider_tools_block '{ type filter hook input priority -1; }' 2>/dev/null || true
nft flush chain inet filter provider_tools_block

# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen:
# nft add rule inet filter provider_tools_block ip saddr 203.0.113.0/24 accept

curl -fsS https://reports.provider.tools/api/v1/abuse/export | while read -r ip; do
  [ -n "$ip" ] && nft add element inet filter provider_tools_block "{ $ip }" 2>/dev/null || true
done
nft add rule inet filter provider_tools_block ip saddr @provider_tools_block drop

Cron (every 5 minutes):

*/5 * * * * root /usr/local/sbin/pt-block-sync-nft.sh
04

ufw (Ubuntu/Debian)

ufw does not have sets - the cleanest way is the ipset + iptables script from the section above: ufw uses iptables under the hood, and a jump to PROVIDER_TOOLS_BLOCK works alongside ufw without conflicts.

Alternatively, block each IP with ufw directly (slower for large lists, suitable for small ones):

#!/usr/bin/env bash
set -e
# Vorherige Einträge entfernen
ufw status numbered | awk '/provider-tools/ {print $1}' | sed 's/[//;s/]//' | sort -rn | while read -r n; do
  yes | ufw delete "$n" >/dev/null 2>&1 || true
done
curl -fsS https://reports.provider.tools/api/v1/abuse/export | while read -r ip; do
  [ -n "$ip" ] && ufw deny from "$ip" comment 'provider-tools' >/dev/null 2>&1 || true
done
05

pf (FreeBSD / OpenBSD / macOS)

Define a table in /etc/pf.conf and load the list into it:

table <provider_tools> persist

block drop in quick from <provider_tools> to any

Sync script (e.g. /usr/local/sbin/pt-block-sync-pf.sh):

#!/bin/sh
set -e
TMP=$(mktemp)
curl -fsS https://reports.provider.tools/api/v1/abuse/export -o "$TMP"

# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen (vor dem Reload löschen):
# sed -i '' '/^203.0.113./d' "$TMP"

pfctl -t provider_tools -T replace -f "$TMP"
rm -f "$TMP"

Cron (every 5 minutes):

*/5 * * * * root /usr/local/sbin/pt-block-sync-pf.sh
06

Windows Firewall

PowerShell script, run as scheduled task every 5 minutes. Blocks the current list via a single dynamic firewall rule:

# pt-block-sync.ps1
$ErrorActionPreference = 'SilentlyContinue'
$ips = (Invoke-WebRequest -Uri 'https://reports.provider.tools/api/v1/abuse/export' -UseBasicParsing).Content -split '\n' | Where-Object { $_ -match '^\d+\.\d+\.\d+\.\d+$' }

Remove-NetFirewallRule -DisplayName 'provider-tools-block'

if ($ips.Count -gt 0) {
    New-NetFirewallRule -DisplayName 'provider-tools-block' -Direction Inbound -Action Block -RemoteAddress $ips -Profile Any
}

Scheduled task:

schtasks /Create /TN "provider-tools-block" /TR "powershell -ExecutionPolicy Bypass -File C:scriptspt-block-sync.ps1" /SC MINUTE /MO 5 /RU SYSTEM

Add your own IPs to a second Allow rule that runs BEFORE this rule - Windows processes allow rules first by default.