What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Order of blacklist and whitelist in skynet

johnsmallberries

New Around Here
I have skynet 8.0.7 and I also run fail2ban on the hosts. I've noticed recently that a lot of IPs in the gitlab CDN (using the skynet default whitelists) are coming through and getting blocked by fail2ban, even though I have the specific IP already banned in skynet from the abuseipdb list. Am I correct in that the order of precedence for skynet is whitelist takes priority over blacklist? Would there be any strategy to reverse that order?
Thanks.
 
Whitelists by nature are supposed to prioritise a blacklist, this is by design. CDN whitelisting can be turned off at your own discretion.
 
That is interesting I had the following and the IP was passed through and eventually hit my fail2ban:

ipset list | egrep '20.102.0.0|20.102.40.205'
20.102.0.0/17 comment "CDN-Whitelist: Github"
20.102.40.205 comment "Imported: AbuseIPDB"
20.102.40.205 is in the Skynet-Blacklist.
Maybe something with the router. I rebooted and will monitor further and mention if the blacklisted ips are not getting trapped even thought there is a whitelist that covers the range.
 
That is interesting I had the following and the IP was passed through and eventually hit my fail2ban:


20.102.40.205 is in the Skynet-Blacklist.
Maybe something with the router. I rebooted and will monitor further and mention if the blacklisted ips are not getting trapped even thought there is a whitelist that covers the range.
The whitelist always negates a blacklist entry. That’s what Adamm likely intended when he said “prioritise a blacklist”. It takes precedence over a blacklist.
 
Oh sorry yeah I interpreted his comments in the reverse. So everything works normally. I guess I'll try getting rid of some of the github CDN ranges or just deal with it through fail2ban. I guess the github CDN infrastructure is popular for attacks these days.
 
Similar threads
Thread starter Title Forum Replies Date
B Diversion Alternate blacklist editing & possible wildcards? Asuswrt-Merlin AddOns 8

Similar threads

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!

Members online

Back
Top