This is a pre-production deployment of Warehouse. Changes made here affect the production instance of PyPI (
Help us improve Python packaging - Donate today!
Project Description


This version is considered experimental. Do not attempt to use this library in production until tests via travis and docker are setup, stable, and sufficiently covered.


You are responsible for rotating log files (/var/log/nfsinkhole*), and syslog forwarding must be configured manually (automation pending).

nfsinkhole is a Python library and scripts for setting up a Unix server as a sinkhole (monitor, log/capture, and drop all traffic to a secondary interface).

The default setup arguments monitor/capture all traffic. Setup arguments are provided to configure protocols, ports, rate limiting, logging, source IP/CIDR exclusions from logging, and optional packet capture.

All sinkhole events are written to /var/log/nfsinkhole-events.log. Optionally, you can enable tcpdump to output packet capture text to /var/log/nfsinkhole-pcap.log if your version of tcpdump supports packet printing; otherwise reverts to /var/log/nfsinkhole.pcap.


  • Simple install script
  • Installs as a init.d/systemctl service
  • Service modifies iptables on start/stop, no need to persist iptables
  • rsyslog and syslog-ng (pending) supported
  • RedHat/CentOS 6/7 tested
  • Python 2.6+ and 3.0+ supported
  • Built-in support for dealing with SELinux/AppArmor
  • Packet capture of sinkhole traffic (printed output to log for tcpdump v4.5+)
  • Useful set of utilities
  • Detailed logging to /var/log/nfsinkhole-*
  • Syslog forwarding configuration (pending)
  • BSD license

Planned Improvements

  • API/class documentation
  • syslog-ng support (currently partially built; unused)
  • Tests via travis-ci/docker
  • Coverage via
  • Exception handling overhaul
  • Set logging level (currently debug)
  • BIND/Microsoft/etc DNS server configuration documentation/examples
  • Monitoring use case examples
  • Automatic configuration for syslog forwarding
  • SIEM parsers/apps/plugins
  • Official support/testing for more OS environments
  • Support handling exceptions for HIPS and other endpoint security products
  • Intelligent handling/handshakes (inspired by iptrap -



iptables (likely already included in base OS)
tcpdump (optional - likely already included in base OS)

Python 2.6:


Python 2.7, 3.0+:




The nfsinkhole service, iptables rules, and tcpdump must run as root. You can still use user/virtualenv Python environments, for the library, but ultimately, the core sinkhole will be run as root.


Replace any below occurence of <INTERFACE> with the name of your sinkhole network interface name.

Base OS (no pip)


GitHub - Stable:

wget -O argparse.tar.gz
tar -C argparse -zxvf argparse.tar.gz
cd argparse
python install --user prefix=
cd ..
rm -Rf argparse
wget -O nfsinkhole.tar.gz
tar -C nfsinkhole -zxvf nfsinkhole.tar.gz
cd nfsinkhole
python install --user prefix=
cd ..
rm -Rf nfsinkhole
python ~/.local/bin/ --interface <INTERFACE> --install --pcap


GitHub - Stable:

wget -O nfsinkhole.tar.gz
tar -C nfsinkhole -zxvf nfsinkhole.tar.gz
cd nfsinkhole
python install --user prefix=
cd ..
rm -Rf nfsinkhole
python ~/.local/bin/ --interface <INTERFACE> --install --pcap


Once installed you need to start the nfsinkhole service.


sudo service nfsinkhole start


sudo systemctl start nfsinkhole.service

Special Thanks

Thank you JetBrains for the PyCharm open source support!


0.1.0 (2016-08-29)

  • Initial release
Release History

Release History


This version

History Node

TODO: Figure out how to actually get changelog content.

Changelog content for this version goes here.

Donec et mollis dolor. Praesent et diam eget libero egestas mattis sit amet vitae augue. Nam tincidunt congue enim, ut porta lorem lacinia consectetur. Donec ut libero sed arcu vehicula ultricies a non tortor. Lorem ipsum dolor sit amet, consectetur adipiscing elit.

Show More

Download Files

Download Files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

File Name & Checksum SHA256 Checksum Help Version File Type Upload Date (37.1 kB) Copy SHA256 Checksum SHA256 Source Sep 22, 2016

Supported By

WebFaction WebFaction Technical Writing Elastic Elastic Search Pingdom Pingdom Monitoring Dyn Dyn DNS Sentry Sentry Error Logging CloudAMQP CloudAMQP RabbitMQ Heroku Heroku PaaS Kabu Creative Kabu Creative UX & Design Fastly Fastly CDN DigiCert DigiCert EV Certificate Rackspace Rackspace Cloud Servers DreamHost DreamHost Log Hosting