Skip to content

Latest commit

 

History

62 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

jamban

This script works in conjunction with a Jamulus server and nftables to kickban users by IP.

requirements

  1. start the Jamulus server (version >= 4.0.0) with the RPC server enabled. Run Jamulus --help for more infos on how to do that
  2. configure nftables to contain a table, chain and set visible to jamban (see jamban.py --help for defaults or below for examples)
  3. the environment variables $JSONRPCPORT and $JSONRPCSECRETFILE must contain the same values as the Jamulus server was launched with (--jsonrpcport and --jsonrpcsecretfile)

  • output of jamban.py --help:
$ jamban --help
usage: jamban [-h] [--timeout [TIMEOUT]] [--banset BANSET] [--unban] [--unbanAll] [--kickListeners] [--kickNoNames] [--list] [--listRaw] [--environmentfile [ENVIRONMENTFILE]]

This script uses nftables to ban clients from Jamulus servers.

        Make sure nftables is installed and has a basic ruleset loaded to which you can add your banset.
        See the included example configurations for nftables (ex*-ruleset.nft)

options:
  -h, --help            show this help message and exit
  --timeout [TIMEOUT], -t [TIMEOUT]
                        set the default bantime, e.g. 30m, 1d, etc. or leave blank for permban (default: 2h)
  --banset BANSET, -s BANSET
                        set the name of the set to be used for the nftables blacklist (default: ip jamban banset)
  --unban, -u           select addresses to unban from the server
  --unbanAll            unban all currently banned clients
  --kickListeners, -L   kick all current listeners
  --kickNoNames, -N     kick all clients named No Name
  --list, -l            list clients as metadata input to icecast
  --listRaw, -r         list raw client details
  --environmentfile [ENVIRONMENTFILE], -f [ENVIRONMENTFILE]
                        path to a systemd environment file containing JSONRPCPORT and JSONRPCSECRETFILE variables

  • included example configurations for nftables:

1: (sudo nft -f ex1-ruleset.nft)

add     table   ip       jamban
add     chain   jamban   input          { type filter hook input priority -1; policy accept; }
add     set     jamban   banset         { type ipv4_addr; flags timeout; size 4096; }
add     rule    jamban   input          ip saddr @banset counter drop

2: (sudo nft -f ex2-ruleset.nft)

table ip jamban {
        set banset {
                type ipv4_addr
                size 4096
                flags timeout
        }

        chain input {
                type filter hook input priority -1; policy accept;
                ip saddr @banset counter drop
        }
}
  • CAUTION: the example configurations can break existing rulesets for nftables.

About

No description or website provided.

Topics

Resources

Stars

2 stars

Watchers

1 watching

Forks

Contributors

Languages