There are 9 repositories under netfilter topic.
Aggregated AbuseIPDB blocklists with worst IPv4 & IPv6 offenders (~99% confidence)
Insert trace-points into the running configuration to observe the path of packets through the iptables chains.
⚔️🧱🔥🛑IP BAN Block Allow GEOIP country traffic limit server input/output to IP countries with iptables+xt_geoip, auto db-ip update, firewall fail2ban gfw ufw cidr blacklist netfilter rules persistent restrict netaddr xtables linux debian ubuntu apache nginx web server anti hack ddos firewalld ipblocks ipdeny ip ranges MaxMind ipset
A Linux kernel IPC firewall and logger for Android and Binder
Geographical host protection for Linux/FreeBSD
Bash script to create nftables sets of country specific IP address ranges for use with firewall rulesets. The project provides a simple and flexible way to implement geolocation filtering with nftables. It can be a useful tool to reduce the chance of malware, ransomware and phishing attempts as well as mitigating the effects of DDoS attacks.
Layer 4 Single Packet Authentication Linux kernel module utilizing Netfilter hooks and kernel supported Berkeley Packet Filters (BPF)
Allow/deny traffic in nftables using country specific IP blocks
c-binding free API for golang to communicate with the queue subsystem of netfilter
Docker container for intercepting packets with scapy from a netfilter queue (nfqueue)
Firegex, a firewall for Attack-Defense CTFs
Transparent TLS and HTTP proxy serve and operate on all 65535 ports, with domain regex whitelist and rest api control
Netfilter Conntrack Stats Exporter
TeaVPN2 - An open source VPN Software (currently supported platform is only Linux).
Opensvp is a security tool implementing "attacks" to be able to test the resistance of firewall to protocol level attack.
The Linux netfilter conntrack-based connection flows pretty printer.
ARP spoofing, HTTP redirection, DNS spoofing and DNS forging using pcap library
Opensnitch / LittleSnitch - No-Gafam (blocklist for facebook, google, microsoft, amazon, huawei, tencent, apple, xiaomi ...) - aggressive privacy and protection (trackers, spywares, malwares, cti feeds, malicious ips, phishing...) - 99% in adsblockers tests !
A plugin of netfilter-persistent in debian/ubuntu to make ipset rules persistent, especially on reboot.
UPPERSAFE Open Source Firewall
This is a repository to develop a web interface to enble configuration of nftables via GUI.
generating problems on RTP streams : latency, delay, jitter
An encryption trial with AES-128 on Linux kernel subsystem Netfilter
nfsinkhole is a Python library and scripts for setting up a Linux server as a sinkhole (monitor, log/capture, and drop all traffic to a secondary interface).