# Ip ranges, cs-firewall-bouncer and nftables

**URL:** <https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296>\
**Category:** Uncategorized\
**Created:** [September 26, 2021, 4:14pm UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296 "2021-09-26T16:14:23Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![lleddewk](https://avatars.discourse-cdn.com/v4/letter/l/e56c9b/32.png) [@lleddewk](https://discourse.crowdsec.net/u/lleddewk)\
**Post date:** [September 26, 2021, 4:14pm UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/1 "2021-09-26T16:14:23Z")

</div>

When using cs-firewall-bouncer with nftables, it does not appear to be possible to ban ranges of ip addresses. For example, after adding a range using `sudo cscli decisions add --range 1.2.3.0/24`, inspecting the content of the crowdsec table using `sudo nft list table ip crowdsec` shows that only ip 1.2.3.0 is banned.

The reason seems to be that the blocklist set definition is missing the “interval” flag (see [Sets - nftables wiki](https://wiki.nftables.org/wiki-nftables/index.php/Sets)). I’m not a go coder but I think changes would be needed in file `nftables.go` around lines 60 and 128.

---

<div class="post-metadata">

**Author:** ![alteredCoder](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/alteredcoder/32/44_2.png) [@alteredCoder](https://discourse.crowdsec.net/u/alteredCoder)\
**Post date:** [September 28, 2021, 9:09am UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/2 "2021-09-28T09:09:47Z")

</div>

Hello @lleddewk ,

Thanks for reporting the issue! We are working on fixing it 🙂

---

<div class="post-metadata">

**Author:** ![Jason](https://avatars.discourse-cdn.com/v4/letter/j/dc4da7/32.png) [@Jason](https://discourse.crowdsec.net/u/Jason)\
**Post date:** [March 5, 2025, 9:27am UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/3 "2025-03-05T09:27:56Z")

</div>

Hi I still have exactly the same problem and I am running:

# cs-firewall-bouncer -V version: - BuildDate: GoVersion: 1.21.13 Platform: linux

on openwrt. Is there a solution to this already?

Thank you very much for your help and time.

Package:  
crowdsec-firewall-bouncer  
0.0.29-1

Openwrt: Powered by LuCI openwrt-23.05 branch (git-24.364.71483-75d2b84) / OpenWrt 23.05.3 (r23809-234f1a2efa)

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [March 6, 2025, 9:32am UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/4 "2025-03-06T09:32:01Z")

</div>

You can find the pull request for range support: [Support ranges in nftables by sbs2001 · Pull Request #85 · crowdsecurity/cs-firewall-bouncer · GitHub](https://github.com/crowdsecurity/cs-firewall-bouncer/pull/85)

Currently though we are unable to proceed with the implementation due to nftables seeing ranges overlapping as a hard error and we couldnt find a solution to this, so currently ranges are not support remediation type in nftables mode.

---

<div class="post-metadata">

**Author:** ![seemebreakthis](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/seemebreakthis/32/1166_2.png) [@seemebreakthis](https://discourse.crowdsec.net/u/seemebreakthis)\
**Post date:** [March 17, 2025, 2:34pm UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/5 "2025-03-17T14:34:44Z")

</div>

Just bumped into the exact same issue over here. Using the bouncer that runs on Openwrt which uses nftables.

Hopefully there can be fix sometime in the future. In the meantime instead of doing something like this on the engine

`cscli decisions add --range 216.218.206.0/24 --duration 2160h`

What do you suggest I should do instead? 255 lines of `cscli decisions add --ip` ? Will Crowdsec see this as spamming their servers (given I see on their web dashboard everything I have banned)?

---

<div class="post-metadata">

**Author:** ![iiAmLoz](https://dub1.discourse-cdn.com/flex013/user_avatar/discourse.crowdsec.net/iiamloz/32/386_2.png) [@iiAmLoz](https://discourse.crowdsec.net/u/iiAmLoz)\
**Post date:** [March 17, 2025, 3:09pm UTC](https://discourse.crowdsec.net/t/ip-ranges-cs-firewall-bouncer-and-nftables/296/6 "2025-03-17T15:09:47Z")

</div>

Personally the best solution would to use a cidr generator like [mapcidr](https://github.com/projectdiscovery/mapcidr)

Then you can do something like this:

```bash
mapcidr --cidr 216.218.206.0/24 | cscli decisions import -i- --format values --duration 2160h

```

This will import all decisions as per IP and only shows as one alert in console.
