How firewall blocking works
No fail2ban needed on the firewall itself. The block list is a plain-text export - one IP per line, only soft- and hard-listed attackers:
https://reports.provider.tools/api/v1/abuse/export (all services)
https://reports.provider.tools/api/v1/abuse/export?service=ssh (single service)
You fetch this list on a schedule (every 5 minutes, like our own sync) and load it into your firewall rule set. Delisted IPs are simply no longer in the list - just rebuild the set each run.
Whitelist first: always exclude your own IPs (office, VPN, monitoring) so you never lock yourself out.
iptables + ipset (Linux)
Save as /usr/local/sbin/pt-block-sync.sh, then chmod +x:
#!/usr/bin/env bash
set -e
IPLIST=$(mktemp)
curl -fsS https://reports.provider.tools/api/v1/abuse/export -o "$IPLIST"
ipset destroy provider-tools-block 2>/dev/null || true
ipset create provider-tools-block hash:ip hashsize 4096 maxelem 65536
while read -r ip; do
[ -n "$ip" ] && ipset add provider-tools-block "$ip" 2>/dev/null || true
done < "$IPLIST"
# Chain anlegen (einmalig) und Regel erzwingen
iptables -N PROVIDER_TOOLS_BLOCK 2>/dev/null || true
iptables -C INPUT -j PROVIDER_TOOLS_BLOCK 2>/dev/null || iptables -I INPUT -j PROVIDER_TOOLS_BLOCK
iptables -F PROVIDER_TOOLS_BLOCK
# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen:
# iptables -A PROVIDER_TOOLS_BLOCK -s 203.0.113.0/24 -j RETURN
iptables -A PROVIDER_TOOLS_BLOCK -m set --match-set provider-tools-block src -j DROP
rm -f "$IPLIST"
Cron (every 5 minutes, matching the network sync):
*/5 * * * * root /usr/local/sbin/pt-block-sync.sh
nftables (Linux)
Save as /usr/local/sbin/pt-block-sync-nft.sh, then chmod +x:
#!/usr/bin/env bash
set -e
nft flush set inet filter provider_tools_block 2>/dev/null || nft add set inet filter provider_tools_block '{ type ipv4_addr; flags interval; }'
nft add chain inet filter provider_tools_block '{ type filter hook input priority -1; }' 2>/dev/null || true
nft flush chain inet filter provider_tools_block
# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen:
# nft add rule inet filter provider_tools_block ip saddr 203.0.113.0/24 accept
curl -fsS https://reports.provider.tools/api/v1/abuse/export | while read -r ip; do
[ -n "$ip" ] && nft add element inet filter provider_tools_block "{ $ip }" 2>/dev/null || true
done
nft add rule inet filter provider_tools_block ip saddr @provider_tools_block drop
Cron (every 5 minutes):
*/5 * * * * root /usr/local/sbin/pt-block-sync-nft.sh
ufw (Ubuntu/Debian)
ufw does not have sets - the cleanest way is the ipset + iptables script from the section above: ufw uses iptables under the hood, and a jump to PROVIDER_TOOLS_BLOCK works alongside ufw without conflicts.
Alternatively, block each IP with ufw directly (slower for large lists, suitable for small ones):
#!/usr/bin/env bash
set -e
# Vorherige Einträge entfernen
ufw status numbered | awk '/provider-tools/ {print $1}' | sed 's/[//;s/]//' | sort -rn | while read -r n; do
yes | ufw delete "$n" >/dev/null 2>&1 || true
done
curl -fsS https://reports.provider.tools/api/v1/abuse/export | while read -r ip; do
[ -n "$ip" ] && ufw deny from "$ip" comment 'provider-tools' >/dev/null 2>&1 || true
done
pf (FreeBSD / OpenBSD / macOS)
Define a table in /etc/pf.conf and load the list into it:
table <provider_tools> persist
block drop in quick from <provider_tools> to any
Sync script (e.g. /usr/local/sbin/pt-block-sync-pf.sh):
#!/bin/sh
set -e
TMP=$(mktemp)
curl -fsS https://reports.provider.tools/api/v1/abuse/export -o "$TMP"
# Eigene IPs NIE blocken - hier Ihre Whitelist pflegen (vor dem Reload löschen):
# sed -i '' '/^203.0.113./d' "$TMP"
pfctl -t provider_tools -T replace -f "$TMP"
rm -f "$TMP"
Cron (every 5 minutes):
*/5 * * * * root /usr/local/sbin/pt-block-sync-pf.sh
Windows Firewall
PowerShell script, run as scheduled task every 5 minutes. Blocks the current list via a single dynamic firewall rule:
# pt-block-sync.ps1
$ErrorActionPreference = 'SilentlyContinue'
$ips = (Invoke-WebRequest -Uri 'https://reports.provider.tools/api/v1/abuse/export' -UseBasicParsing).Content -split '\n' | Where-Object { $_ -match '^\d+\.\d+\.\d+\.\d+$' }
Remove-NetFirewallRule -DisplayName 'provider-tools-block'
if ($ips.Count -gt 0) {
New-NetFirewallRule -DisplayName 'provider-tools-block' -Direction Inbound -Action Block -RemoteAddress $ips -Profile Any
}
Scheduled task:
schtasks /Create /TN "provider-tools-block" /TR "powershell -ExecutionPolicy Bypass -File C:scriptspt-block-sync.ps1" /SC MINUTE /MO 5 /RU SYSTEM
Add your own IPs to a second Allow rule that runs BEFORE this rule - Windows processes allow rules first by default.
Related articles
Attack Defense - What it is & how it works
The product explained from zero: report attacks from your servers to a global list - and automatically block reported attackers on your own systems. Free, anonymous, GDPR compliant.
ReadOn your server: fail2ban (reporting & auto-blocking)
One command installs reporting AND automatic blocking of reported attackers on your server - with block consumer, 5-minute sync, whitelist and per-service filtering.
ReadCheck IPs: Live Check & DNS
Check whether an IP is listed: web Live Check or dig against the per-service check zones - with return codes, TXT details and the HTTP export.
Read