Nftables chokes on very large sets

Yeah, I fully appreciate the limitations of geoip databases, especially the free versions :slight_smile:

I can just drop the US ranges for now, but I've asked on the banIP thread about whether it's possible to create a custom local feed that I can keep up to date myself based on the "more accurate" db-ip database.

EDIT: It turns out the "more accurate" db-ip database classifies that UK IP as being located in the Netherlands, so it's wrong as well but it "works" in my scenario.