vim /etc/nftables.conf
...
table inet filter {
set blacklist-v4 {
type ipv4_addr
flags interval
auto-merge
elements = { 185.176.221.167, 81.30.158.0/24, 213.137.128.0/19 }
}
...
# accept traffic originated from us
ct state established,related accept
# drop ip form blacklist
ip saddr @blacklist-v4 drop
....
service nftables restart
https://forum.iredmail.org/topic16335-nftables-rule-no-ping-floods.html