Iptables block ip address – Security Shell Script

Create /root/iptables/blocked.ips file as follows with list of ips and subnets to block entering your dedicated server:
# spam

Call following script from your existing shell script:

# Simple iptables IP/subnet block script 
# -------------------------------------------------------------------------
# Copyright (c) 2004 nixCraft project <http://www.cyberciti.biz/fb/>
# This script is licensed under GNU GPL version 2.0 or above
# -------------------------------------------------------------------------
# This script is part of nixCraft shell script collection (NSSC)
# Visit http://bash.cyberciti.biz/ for more information.
# ----------------------------------------------------------------------
BADIPS=$(egrep -v -E "^#|^$" /root/iptables/blocked.ips)
# create a new iptables list
for ipblock in $BADIPS
   $IPT -A $SPAMLIST -s $ipblock -j LOG --log-prefix "$SPAMDROPMSG"
   $IPT -A $SPAMLIST -s $ipblock -j DROP
🐧 Get the latest tutorials on SysAdmin, Linux/Unix, Open Source, and DevOps topics via:
Category List of Unix and Linux commands
Disk space analyzers ncdu pydf
File Management cat
Firewall Alpine Awall CentOS 8 OpenSUSE RHEL 8 Ubuntu 16.04 Ubuntu 18.04 Ubuntu 20.04
Network Utilities NetHogs dig host ip nmap
OpenVPN CentOS 7 CentOS 8 Debian 10 Debian 8/9 Ubuntu 18.04 Ubuntu 20.04
Package Manager apk apt
Processes Management bg chroot cron disown fg jobs killall kill pidof pstree pwdx time
Searching grep whereis which
User Information groups id lastcomm last lid/libuser-lid logname members users whoami who w
WireGuard VPN Alpine CentOS 8 Debian 10 Firewall Ubuntu 20.04
9 comments… add one
  • Erik Jan 16, 2012 @ 22:53

    i have a ip that i want to block in my dreambox ???


  • gamecp Mar 30, 2011 @ 14:58

    great script!

  • dodger Jul 5, 2010 @ 12:34

    thanks for this script..
    btw i have some error with “BADIPS=$(egrep -v -E “^#|^$” /root/iptables/blocked.ips)”
    with -E swich… i change it to -e and its work fine
    in egrep –help no -E option

    ubuntu 10.04

  • peace Feb 23, 2010 @ 20:51

    hi i new to iptables where exactly should i write this script any help
    thanks for any help appreciated.

  • Andre Oct 28, 2009 @ 18:53

    i wanna allow just this ip [ –,,] and block other ip how is the configuration.
    please send to my email : nseshop@gmail.com

    thanks very much

  • parbat Jun 24, 2009 @ 13:05


    everybody now will come big platform

  • Charon Jun 19, 2009 @ 12:45

    I think rule
    is incorrect. Because in this case $ipblock is destination (-d), not source (-s)

  • Igor May 29, 2009 @ 0:55

    How can I remove ip’s from blocked

    • Ghulam Sakhi Jun 29, 2011 @ 10:49

      Dear Reader.
      you can remove IP from block by this short command
      #iptables -D input -s IP ADDRESS -j DROP is an example you can remove any IP that you want just type instate

Leave a Reply

Your email address will not be published.

Use HTML <pre>...</pre>, <code>...</code> and <kbd>...</kbd> for code samples.