Please help me with banip

I am trying to configure banip on my home network to keep the nasties out. I live in the USA. Should I block connections outside the USA? I have never used banip before. Could you guys please tell me what I need to do to get it setup and implemented using luci interface? I am not trying to block ads with it. I just want to block bad ips, malware, and anything else that would help secure my network.

I have tried using ChatGPT to help me configure banip. I have also searched Google and Reddit. I cannot find some of the settings referenced in the guides. For example it says there should be a tab for selecting the block lists. I went through all the tabs in banip and could not find it anywhere. Please give me a hand guys. I am trying to work on expanding my knowledge now that I have the basics figured out on how to configure openwrt.

On LuCi, go to the top menu Services –> BanIP

Then, scroll down until you find the section “Settings” where you will see a tab called “Feed Selection”

Then you will see a drop-down menu where you can select the lists available.

I have selected:

bruteforceblock
cinsscore
debl
firehol1
greensnow
ipthreat
threat
turris

And some countries like USA (I’m not in the USA), China, Russia, India, Iran, Ukraine, North Korea, Venezuela.

More help, here:

https://forum.openwrt.org/t/banip-support-thread/

1 Like

Start with the official readme: https://github.com/openwrt/packages/blob/e09ffebce1b12fe883071e845ec1d618a15e00f3/net/banip/files/README.md

…and join the dedicated banIP support thread here in the forum (also referenced in the readme).

2 Likes

Thank you so much for your help. All the guides I came across using Google searches seamed be older versions. The settings they told me to change did not exist. I could not find a single YouTube video either.

One question I have is when I select the countries is it for blocking traffic from them or to allow traffic?

Thank you so much for the response and info. This is what I needed. Google searches and stuff were doing no justice.

I have done as you suggested. I have picked a few feed lists. I was confused about the RIR section. Under feed selection there is two options for RIR. One is just labeled RIR and the other is Regional mIntegrity Registry. Would I set both of these to ARIN? I then set the startup triggers to WAN and WAN6. Is there anything I configured wrong or anything else I should do? Thank you once again. I appreciate your help greatly.