Nftables + Krawl Integration
April 8, 2026 ยท View on GitHub
Automatically block malicious IPs detected by Krawl using nftables firewall rules.
Prerequisites
- Modern Linux system with nftables installed (Ubuntu 22+, Debian 12+, RHEL 9+)
- Krawl running with API accessible
- Root/sudo access
- Curl for HTTP requests
- Cron for scheduling
Check if your system uses nftables
sudo nft list tables
If this returns tables, use nftables. Otherwise, use iptables.
Quick Setup
1. Create the script
#!/bin/bash
KRAWL_URL="https://your-krawl-instance/your-dashboard-path"
curl -s "${KRAWL_URL}/api/export-ips?categories=attacker&fwtype=nftables" > /tmp/krawl_nftables_rules.sh
sudo bash /tmp/krawl_nftables_rules.sh
rm -f /tmp/krawl_nftables_rules.sh
echo "Krawl nftables rules updated"
Save as krawl-nftables.sh and make executable:
chmod +x krawl-nftables.sh
2. Test it
sudo ./krawl-nftables.sh
3. Schedule with Cron
sudo crontab -e
Add this line to update rules every hour:
0 * * * * /path/to/krawl-nftables.sh
Commands
View blocked IPs
sudo nft list set inet filter blacklist
Count blocked IPs
sudo nft list set inet filter blacklist | grep "elements" | wc -w
Manually block an IP
sudo nft add element inet filter blacklist { 192.0.2.100 }
Manually unblock an IP
sudo nft delete element inet filter blacklist { 192.0.2.100 }
View all rules
sudo nft list table inet filter
Clear all blocked IPs
sudo nft flush set inet filter blacklist
How It Works
- Script fetches nftables-formatted rules from Krawl API (
/api/export-ips?categories=attacker&fwtype=nftables) - Executes the downloaded bash script
- Creates
inet filtertable andblacklistset - Drops all traffic from blacklisted IPs immediately