A CLI tool for fetching and managing CIDR IP ranges from RIRs with firewall integration.
Project description
CIDRe is a CLI tool that fetches daily updated IP allocations from Regional Internet Registries (RIRs), compiles them into country-based CIDR files, and allows easy firewall management.
🔹 Supports AFRINIC, APNIC, ARIN, LACNIC, RIPE NCC
🔹 Daily automatic CIDR updates in the repository
🔹 Merges and optimizes CIDR blocks for efficiency
🔹 Firewall integration (UFW & iptables /w ipset support)
🔹 IPv4 & IPv6 compatible
⚡ Quick start
1️⃣ Install CIDRE
pip install cidre-cli
2️⃣ Pull & merge CIDR ranges
cidre pull --merge
- Downloads the latest CIDR allocations from RIRs.
- Merges overlapping IP ranges for efficiency.
3️⃣ Block specific countries
# UFW is better suited for small CIDR inputs
cidre deny ir kp --firewall ufw
- Blocks Iran (IR), and North Korea (KP) in UFW.
- Requires ufw installed (
sudo apt install ufw).
# iptables is better suited for large CIDR inputs
cidre deny ru ir kp --firewall iptables
- Blocks Russia (RU), Iran (IR), and North Korea (KP) in iptables using ipset.
- Requires ipset and iptables installed (
sudo apt install ipset iptables).
🛠️ Installation
1️⃣ Install via PyPI
pip install cidre-cli
2️⃣ Alternative: clone the repository
git clone https://github.com/vulnebify/cidre.git
cd cidre
python3 -m venv .venv
source .venv/bin/activate
pip install .
⚡ Usage
1️⃣ Pull and compile CIDR ranges
Fetches the latest IP allocation data from all RIRs and compiles per-country CIDR blocks:
cidre pull --merge
--merge: Merges overlapping IP ranges for efficiency.--proxy <proxy>: Proxies connection to RIRs.--cidr-store <path>: Specifies CIDRs' custom storage directory. Default./output/cidr/{ipv4|ipv6}/{country_code}.cidr.
2️⃣ Action on countries
Allow|deny|reject specific countries' CIDR blocks in specified firewall:
cidre allow|deny|reject ru ir kp
--firewall ufw|iptables: Firewall to apply rules. Defaultufw.--cidr-store <path>: Specifies CIDRs' custom storage directory. Default./output/cidr/{ipv4|ipv6}/{country_code}.cidr.
⚠️ NOTE: iptables firewall DO NOT persist rules by default
To ensure iptables and IPSet rules persist after a reboot, follow these steps:
# 1️⃣ Save rules based on the firewall method:
# - For iptables + IPSet:
sudo ipset save > /etc/ipset.rules
sudo iptables-save > /etc/iptables/rules.v4
sudo ip6tables-save > /etc/iptables/rules.v6
# 2️⃣ Restore firewall rules on boot:
# - For iptables + IPSet:
sudo bash -c 'echo "ipset restore < /etc/ipset.rules" >> /etc/rc.local'
sudo chmod +x /etc/rc.local
# 3️⃣ Reboot and verify:
sudo reboot
sudo ipset list
sudo iptables -L -v -n
📄 License
This project is licensed under the MIT License.
🙌 Inspired by
CIDRE was inspired by herrbischoff/country-ip-blocks and aims to provide an automated alternative with firewall integration.
🤝 Contributions
PRs are welcome! Feel free to fork the repo and submit pull requests.
📧 Contact
For any questions, open an issue or reach out via GitHub Discussions.
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file cidre_cli-1.1.5.tar.gz.
File metadata
- Download URL: cidre_cli-1.1.5.tar.gz
- Upload date:
- Size: 9.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.10.16
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
2ce075630308b38b7c456074ce34e8134e2e46b46724263ea1a420e418636cbc
|
|
| MD5 |
9d7da1ebe3b1d1a6877380c7c4a7f218
|
|
| BLAKE2b-256 |
3237611c58c4769a0a9e1252767557e5ec237440ce39113d0250b38c316f9caa
|
File details
Details for the file cidre_cli-1.1.5-py3-none-any.whl.
File metadata
- Download URL: cidre_cli-1.1.5-py3-none-any.whl
- Upload date:
- Size: 10.2 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? No
- Uploaded via: twine/6.1.0 CPython/3.10.16
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
3da23c1b7ec195e69dc3f00bebb36001f894d853b2422ba17c1413dd61b14eb8
|
|
| MD5 |
423552f2c670f2a08971ce71ac0899ea
|
|
| BLAKE2b-256 |
ea27899c88525508db0c37f558d28be73434ceab524394fa558bb526abe0cc21
|