yum upgrades for production use, this is the repository for you.
Active subscription is required.
Technical Briefing: Trusted IP List Packages for FirewallD, NGINX, and fail2ban
The Problem
Hardcoded allowlists for services like Stripe webhooks, Cloudflare, and Googlebot go stale silently. When vendors rotate their published IP ranges, existing allowlists stop matching — breaking integrations or blocking legitimate traffic without any obvious failure signal.
The Fix
The GetPageSpeed trusted-lists project packages current, officially published IP ranges for 30+ services as RPM packages. A dnf update refreshes the ranges from the vendor’s authoritative source.
How It Works
A generator fetches ranges directly from vendor endpoints — for example cloudflare.com/ips, openai.com/gptbot.json, Google’s crawler ranges, and Stripe’s webhook list. Package versions derive from the upstream publication timestamp (e.g. firewalld-ipset-cloudflare-v4-20251215), and packages rebuild only when ranges actually change. A routine dnf update picks up new ranges within a day or two of publication.
Two Package Families
firewalld-ipset-*— registers an ipset with FirewallD; post-install runsfirewall-cmd --reload.nginx-iplist-*— ships three include files in/etc/nginx/iplist/; post-install runsnginx -tand reloads NGINX when active.
Both reload consumers automatically, so unattended dnf-automatic updates take effect immediately.
Platform Support
RHEL-based distributions — RHEL, AlmaLinux, Rocky Linux, Oracle Linux, and CentOS Stream — versions 8, 9, and 10, from the GetPageSpeed repository. Packages are architecture-independent (noarch), so x86_64 and ARM share the same packages. Debian and Ubuntu packages are not available yet.
Installation
sudo dnf -y install https://extras.getpagespeed.com/release-latest.rpm
sudo dnf -y install firewalld-ipset-cloudflare-v4 nginx-iplist-cloudflare-v4
Package naming is firewalld-ipset-<list> or nginx-iplist-<list>. Lists published separately for IPv4/IPv6 carry a -v4/-v6 suffix.
FirewallD Usage
Installing a firewalld-ipset-* package registers the ipset immediately — verify with firewall-cmd --get-ipsets. To whitelist system-wide, attach it to the trusted zone:
sudo firewall-cmd --permanent --zone=trusted --add-source=ipset:cloudflare-v4
sudo firewall-cmd --reload
Attaching to the drop zone instead blocks the service outright — the standard approach for unwanted AI crawlers.
NGINX Usage
Each package provides three access-control patterns:
<list>.geo.conf— defines ageoblock setting$is_<list>to1for matching IPs (hyphens become underscores). Include athttplevel. Tested on Rocky Linux 10 with NGINX 1.28: a local address yieldscf=0, a Cloudflare address yieldscf=1.<list>.allow.conf— plainallowdirectives; include in alocationfollowed bydeny all;. Tested: Stripe webhook address3.18.12.63gets HTTP 200, others get HTTP 403.<list>.nolimit.conf— bare geo entries mapping trusted CIDRs to an empty string, whichlimit_reqtreats as “don’t count.” The pattern uses amapto route trusted addresses to an empty$rate_limit_key. Burst test: an ordinary client gets200 429 429 200 429 429; the Googlebot address34.22.85.1gets six consecutive 200s.
Gotcha
allow/deny run in NGINX’s access phase, but return runs earlier in the rewrite phase. A location containing only return answers before access control runs — always pair the allow variant with real content handling (proxy_pass, try_files, static files), never a bare return.
Raw CIDR Access
Every nginx-iplist-* package drops the raw list into /usr/share/trusted-lists/plain/<list>.txt, one CIDR per line, for downstream scripts and daemons.
fail2ban Integration
The fail2ban-trusted-lists-helper package exempts every installed trusted list from all jails at once. It wires a [DEFAULT] ignorecommand into /etc/fail2ban/jail.d/00-trusted-lists.local, pointing at a helper that matches candidate IPs against /usr/share/trusted-lists/plain/ using grepcidr. Requires EPEL:
sudo dnf -y install epel-release
sudo dnf -y install fail2ban-trusted-lists-helper
Verify with fail2ban-client get sshd ignorecommand. The helper script also works standalone:
/usr/share/trusted-lists/scripts/fail2ban-ignoreip-check 3.18.12.63 && echo trusted
Automation
Enable dnf-automatic so vendor range changes apply without intervention:
sudo dnf -y install dnf-automatic
sudo systemctl enable --now dnf-automatic-install.timer
Related Tooling
fds(FirewallD Made Easy) for country and Tor blocking.- An NGINX honeypot for automatic bot banning.
- GetPageSpeed Amplify for scheduled
gixyscans tied to live NGINX runtime metrics, drop-in compatible with the deprecatednginx-amplify-agent(EOL January 2026).
Missing services can usually be packaged within a day on request.
Read the full article: Trusted IP Lists for FirewallD, NGINX and fail2ban
