Marcus Yansen
Regular Contributor
thank you so much!I believe:
filter.list = not aggregated
myfilter.list = aggregated
My limited understanding would be if going with one of those, go with aggregated.
thank you so much!I believe:
filter.list = not aggregated
myfilter.list = aggregated
My limited understanding would be if going with one of those, go with aggregated.
/usr/sbin/curl -s "https://raw.githubusercontent.com/Adamm00/IPSet_ASUS/08d0c3e47a96d843dba8e33101b6644eb8205cee/firewall.sh" -o "/jffs/scripts/firewall" && chmod 755 /jffs/scripts/firewall && sh /jffs/scripts/firewall install
This is my firewall
hackertarget.com
IP-based firewall
@SomeWhereOverTheRainBow Hi, I've been using your list with currently Skynet 8.0.9, but I've been running into an issue I'm unable to solve.Here is a fully aggregated list, to each their own, but it blocks alot. https://raw.githubusercontent.com/jumpsmm7/GeneratedAdblock/refs/heads/master/myfilter.list , I would consider my aggregated list heavily aggressive, and if you are looking for less aggressive @Viktor Jaep may be better if it can be shrunk to an aggregated form.
This comment is key here:@SomeWhereOverTheRainBow Hi, I've been using your list with currently Skynet 8.0.9, but I've been running into an issue I'm unable to solve.
I'm running a Jellyfin server and when I try to look up alternative show/movie images, skynet is blocking it with your list. When I reset the skynet list back to the default list, it works. The specific url that's being blocked is: tmdb-image-prod.b-cdn.net.
It's impossible to allow every ip from the cdn and the ip seems to (almost) change on every lookup... In skynet settings CDN Whitelisting is set to enabled.
Is there anything I (or you?) can do to allow all the ip's behind tmdb-image-prod.b-cdn.net?
It may be impossible to be sure that the IP I would be allowlisting would match the IP that is being blocked by your skynet. The only way to be absolutely sure to allowlist something like tmdb-image-prod.b-cdn.net I would recommend allowlisting the ASN the domain originates from -- AS49434 a.k.a BUNNYCDN or AS200325. You can allowlist an entire ASN using the instructions provided by skynets github. You may also want to consider allowlisting ASN associated with Datacamp AS60068 and AS212238. The domain also has ties to this network. The IP addresses used maybe from any one of these three ASN depending on a number of factors including requester geographic location.It's impossible to allow every ip from the cdn and the ip seems to (almost) change on every lookup...
curl "https://api.hackertarget.com/aslookup/?q=$(dig tmdb-image-prod.b-cdn.net A +short)&output=json&details=true" | jq
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 370 100 370 0 0 559 0 --:--:-- --:--:-- --:--:-- 561
{
"asn": "60068",
"asn_name": "CDN77 _, GB",
"asn_range": "152.233.22.0/23",
"description": "Datacamp Limited is a company in the technology industry that provides online educational courses and resources focused on data science, software development, and other tech-related fields.",
"domain": "datacamp.co.uk",
"ip": "152.233.22.97",
"organization": "Datacamp Limited"
}
curl "https://api.hackertarget.com/aslookup/?q=$(dig tmdb-image-prod.b-cdn.net AAAA +short)&output=json&details=true" | jq
% Total % Received % Xferd Average Speed Time Time Time Current
Dload Upload Total Spent Left Speed
100 393 100 393 0 0 658 0 --:--:-- --:--:-- --:--:-- 658
{
"asn": "200325",
"asn_name": "BUNNYCDN, SI",
"asn_range": "2400:52e0:1a02::/48",
"description": "BUNNYWAY, informacijske storitve d.o.o. is a Slovenian company providing information technology services, including cloud computing and content delivery network (CDN) solutions.",
"domain": "bunnycdn.com",
"ip": "2400:52E0:1A02::876:1",
"organization": "BUNNYWAY, informacijske storitve d.o.o."
}
for i in AS49434 AS60068 AS200325 AS212238; do firewall whitelist asn "$i"; done
If you run into problems later it is likely the server has switched to an IP in one of the other ASN in the list above. I only showed the ipv6 to show that it even uses those ASN to get an ipv6 address. And it can use a different ASN for each address at any given point in time. Just make sure you allow list the appropriate ASN's you should see less issues.@SomeWhereOverTheRainBow Thank you so much for your extensive and informative answer.
I was aware of the ASN option, but had no knowledge on how to query them.
I did get a different ASN (212238) from my A query and have only added this so far to the whitelist as I'm not using ipv6 (for now...still).
Seems to be working for now, but will add additional ones if needed.
Well i know you mentioned the default list not having this problem, but i would recommend @Adamm considering adding the above mentioned ASNs@SomeWhereOverTheRainBow Hi, I've been using your list with currently Skynet 8.0.9, but I've been running into an issue I'm unable to solve.
I'm running a Jellyfin server and when I try to look up alternative show/movie images, skynet is blocking it with your list. When I reset the skynet list back to the default list, it works. The specific url that's being blocked is: tmdb-image-prod.b-cdn.net.
It's impossible to allow every ip from the cdn and the ip seems to (almost) change on every lookup... In skynet settings CDN Whitelisting is set to enabled.
Is there anything I (or you?) can do to allow all the ip's behind tmdb-image-prod.b-cdn.net?
AS49434 AS60068 AS200325 AS212238 to his CDN whitelisting. One of these domains ip addresses could easily wind up in skynets defaults in the future, or even accidently bleed over from diversion shared list.I already did. I'll keep adding as they come. (in this case it was AS60068)If you run into problems later it is likely the server has switched to an IP in one of the other ASN in the list above. I only showed the ipv6 to show that it even uses those ASN to get an ipv6 address. And it can use a different ASN for each address at any given point in time. Just make sure you allow list the appropriate ASN's you should see less issues.
| Thread starter | Title | Forum | Replies | Date |
|---|---|---|---|---|
| H | Diversion Error when block list updates | Asuswrt-Merlin AddOns | 22 | |
| R | Diversion Diversion doesn’t block youtube ads? | Asuswrt-Merlin AddOns | 31 | |
| C | Diversion Custom block list stopped working | Asuswrt-Merlin AddOns | 8 | |
| B | Skynet Block entire regions? | Asuswrt-Merlin AddOns | 14 |
We use essential cookies to make this site work, and optional cookies to enhance your experience.