banIP support thread

SO SORRY :slight_smile: yes, of course domain name - has multiple IPs, and these, change, I’m no expert in DNS, but use nslookup and many other tools.. I have no doubt that placed the first domain name, banip loaded a set of IPs (i.e. “ALL” that nslookup returned at that time), however, the domain kept working, in response to a ping, my suspicious, is that given that banip blocked, say 10 ips, the subsequent ping failed, and internally did another “nslookup” to pull more IPs, and then, started working on a totally NEW IP. I kept doing that about 10-15 times, i.e. each time added the new IP manually to the banip block, reloaded, and still, ping would “find” another IP, that previously did not show up in the nslookup.

nothing else changes as the DNS servers are fixed to 1.1.1.1 and not the ISP..

I think it’s GOOD that it is ADDING (as needed), but i think to REMOVE is probably not a good idea, due to the above description, that an nslookup is LIMITED in the amount of IPs it can return, even if the domain has, say 50 IPs globally, then it would return say 10 to my region, and those would be blocked, but, as mentioned, i think the blocking is “triggering” further nslookup to maybe find an alternate IP, and then ping DOES WORK on a new ip :slight_smile:

so, if now banip would REMOVE prior ones, the next ping will find them, and so forth.

I think to add is good, as it would expand the set of inclusion, the removal should be more on the user end, like suggested before, if one feels it’s overly blocked, they can grep/remove the auto-added, and leave just the domain names, and let banip rebuild the block on the next reload.

Sorry for the confusion of the ip vs domain name, innocent typo that caused u to think i’m a total clueless, which is, pretty far from reality, but, such is world today, not much trust between entities :slight_smile:

Hope to regain your trust and respect your time, way beyond you can imagine.. will try to find some time to look into it more deeply and also contribute later.

Stormy.

BanIP is blocking about 10000 IPs daily.

My lists are reloaded every day and the logs reset when BanIP is restarted.

Is there any way to save the IPs banned, in an incremental way?

Thanks

done with 2a43f4f

1 Like

trying to load this source to banip:

https://raw.githubusercontent.com/Ruddernation-Designs/Adobe-URL-Block-List/refs/heads/master/hosts

went to custom feed, clicked FILL, noticed many sources are out dated, host not found, so deleted, now adding the above, not sure which format the IPv4 should be set to?

which one from this list?

That list is a hosts file list for DNS, such as Adblock. banip needs a list of IP addresses (not 0.0.0.0).

Can someone check that setting custom directories for work/backup/report works in version 1.5.6-r7? that is latest for 24.10.

They do not work now, their path does not change from default, and i remember well that they worked in previous 1.5.6-r4 or 5

I see recent files in my custom directories here.

root@OpenWrt:/mnt/sda1/banip-backup# ll
drwxr-xr-x 2 root root 4096 Aug 29 06:56 ./
drwxr-xr-x 19 root root 4096 Aug 6 04:30 ../
-rw-r--r-- 1 root root 207 Aug 29 04:00 banIP.allowlist.gz
-rw-r--r-- 1 root root 6340 Aug 29 04:00 banIP.bruteforceblock.v4.gz
-rw-r--r-- 1 root root 53961 Aug 29 04:00 banIP.cinsscore.v4.gz
...

Note if the custom path is not available it goes back to using a default in /tmp For example I deleted my /mnt/sda1/banip-reportdirectory and hitting refresh at the bottom of Set Reporting creates a /tmp/ban-IP-report/ directory and puts files there. Also the custom directories have to already exist - it won’t create them.

1 Like

How about add a function, sometimes it is an IP set to try login my Openwrt, can we detect 3 or 5(user can set) identical subnets, and then directly put this subnet into the blacklist whit CIDR format, without expiring?

like this

Mon Sep 1 13:01:13 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.210'
Mon Sep 1 13:01:20 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.210'
Mon Sep 1 13:01:27 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.42'
Mon Sep 1 13:01:33 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.208'
Mon Sep 1 13:01:40 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.210'
Mon Sep 1 13:01:47 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.208'
Mon Sep 1 13:01:54 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.42'
Mon Sep 1 13:02:00 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.208'
Mon Sep 1 13:02:07 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.208'
Mon Sep 1 13:02:14 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.42'
Mon Sep 1 13:02:20 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.42'
Mon Sep 1 13:02:27 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.194'
Mon Sep 1 13:02:34 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.208'
Mon Sep 1 13:02:37 2025 user.info banIP-1.5.6-r7[23134]: add IP '42.48.248.208' (expiry: 1d) to blocklist.v4 set
Mon Sep 1 13:02:44 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.210'
Mon Sep 1 13:02:50 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.194'
Mon Sep 1 13:02:57 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.210'
Mon Sep 1 13:03:00 2025 user.info banIP-1.5.6-r7[23134]: add IP '42.48.248.210' (expiry: 1d) to blocklist.v4 set
Mon Sep 1 13:03:14 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.42'
Mon Sep 1 13:03:17 2025 user.info banIP-1.5.6-r7[23134]: add IP '42.48.248.42' (expiry: 1d) to blocklist.v4 set
Mon Sep 1 13:03:24 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.194'
Mon Sep 1 13:03:37 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.194'
Mon Sep 1 13:03:44 2025 user.info banIP-1.5.6-r7[23134]: suspicious IP '42.48.248.194'
Mon Sep 1 13:03:47 2025 user.info banIP-1.5.6-r7[23134]: add IP '42.48.248.194' (expiry: 1d) to blocklist.v4 set

then

add my ‘42.48.248.1/24’ to my blacklist

Subnet blocking is already implemented, just set the options below to your needs:

1 Like

Not sure if I should report this in the packages repository, since I don't know if this is a bug or just a end-user configuration error, so let me know if I should file an issue!

A tip from personal experience for anyone who had banIP lock up on them (i.e when /etc/init.d/banip stop or /etc/init.d/banip restart would not help). When you have more than 1-2 upstreams (e.g wan, wan6 and a Wireguard client) and/or the upstreams are inconsistent, e.g if you restart or stop all upstream interfaces for whatever reason[1], banIP daemon might "lock up" and stop responding to service management commands like stop, restart, start etc. unless you either reboot or manually unlock it. In LuCI this is represented by opening banIP service page, seeing service management buttons light up for a second and then dim back, meaning you cannot use them even if you change settings. I assume this is because banIP keeps trying to listen on interface even if it has been stopped or disabled.

I'm not sure if this is specific to having "auto detection" enabled or this is just something that may happen in general. But I definitely could experience this with auto detection enabled, and so far I haven't tried restarting interfaces or messing around with them ever since I've manually selected wan devices.

[1] - I have to restart my PPPoE interface if I stop the Wireguard tunnel interface, as if I don't do that wan traffic does not pass through due to I assume Wireguard peer route leftovers.

Steps to reproduce

  • Setup wan and another upstream, preferably a VPN tunnel like Wireguard

  • Install and enable banIP

  • Observe that banIP service works, and responds to service management commands (i.e stop, start, restart, reload)

  • Restart or stop either some or all interfaces

Workaround

  • Delete lock files and folders (careful with those, do not just do this unless you have a good reason to like trying to un-stuck a stuck service):

    • /var/run/lock/procd_banip.lock (file)

    • /var/run/lock/banip.lock (folder)

  • Restart banIP service: service banip restart

Hopefully somebody will find this useful.

I don't get your issue at all, esp. without your config and debug logs ... I've never seen orphaned interfaces in banIP. Regarding auto-detection the online readme is quite clear:

2 Likes

I can confirm on @dibdot response to you. You need to disable “Auto Detection”.

I’ve got multiple WANs plus a few Wireguard interface and I haven’t had issues with BanIP.

2 Likes

Yeah sorry for no logs or configurations, for the former I didn't have debug/verbose output enabled so the logs might've been so-so in terms of verbosity and for the latter I didn't think was necessary, and should've been doable from a clean install... Annoyingly, I turned auto-detection back on to try to reproduce the issue again and I can't seem to get it to get into the locked up state... :grimacing: I'll keep debug logs enabled and if it ever locks up again I'll try to post everything relevant.

Also yes I already disabled auto detection and manually pointed to the wan interface, I did that before even posting here, I just forgot to do that after configuring a VPN tunnel. Though I didn't even think it would cause issues with service being stuck, maybe being ineffective because it listens at the wrong uplink sure, but not full on lockup...

Perhaps wording in the readme could be tweaked a little bit to include in bold letters (for people like me) that if special tunnel interfaces, i.e VPN tunnels are on the network, auto detection must be disabled and interfaces must be assigned manually or at best banIP won't be effective and at worst can cause issues in certain network setups?

P.S I also tried edited my original post to include proper solution i.e disable auto detection and maybe increase trigger delay, in case anyone runs into this weird, rare lockup in the future but I can't seem to edit posts that have been in the thread for a while...

Way ahead of ya :wink: But still, thank you for confirming!

i´m not sure this is doable, or even how to explain it but i´ll give it a try

I blocking all countries execpt of one (.se) for incomming traffic

i would also like to block traffic to (for example) .ru and .ch

but it seems if i´m blocking everything (except .se) incomming that is the only rule i can use is to block everything except .se …is that true or can i somehow make rules to block all trafick to .ru and .ch ?

/b

The question is, to block all or only cn, ru or do you mean really ch????

i´m able to block all incomming traffic except from .se, that works fine

but what i would like to do is block all client traffic going to .ru and .ch

and block all incomming traffic from other then .se
in banip it´s eather or, cant seperate the rules from what i understand

Then select Russia(ru) and Switzerland(ch) in country selection countries(rir) feed only…and select blocklist country.

i´m sorry i dont follow you, bare with me

if i put country in both

Inbound Feed

Outbound Feed

with .ru it will prevent my clients from reaching .ru but nothing will stop for example .us from incomming traffic to my router

Did you understand the tabs feed/set setting and feed section?

Where excatly is your issue?

And I ask you again…