tmpfs.tech · all tracks · Firewall (nftables)

Block IPs with a named set

Firewall (nftables) · medium · live throwaway Linux box · 3 tiered hints

Extend /etc/nftables.conf: define a named set 'blocklist' of ipv4 addresses and an input rule that drops packets whose source is in @blocklist. Keep a base table inet filter / input chain.

▶ Start this challenge

Nobody has solved this one yet — be the first clear on the leaderboard.

How it works

Press start and you get your own real, disposable Linux VM — in the browser terminal or over SSH. Work the task on a live system; tmpfs.tech grades your solution automatically against the actual machine state, then throws the box away. No install, free to try as a guest.

More Firewall (nftables) challenges

Author and reason about nftables rulesets — filtering, NAT and policy.

See all Firewall (nftables) challenges →

FAQ

Is it free? Yes — play as a guest, no signup required to start.

Do I need to install anything? No. Everything runs in your browser, or connect over SSH if you prefer your own terminal.

How is it graded? Automatically and deterministically — your work is checked against the real state of the machine you worked on.