# Как заблокировать диапазон IP-адресов? "Screened IPs" не блокируются

**URL:** https://meta.discourse.org/t/how-to-block-an-ip-range-screened-ips-not-being-blocked/386851
**Category:** Support
**Created:** [27.Октябрь.2025 17:32:58 UTC](https://meta.discourse.org/t/how-to-block-an-ip-range-screened-ips-not-being-blocked/386851 "2025-10-27T17:32:58Z")
**Posts on this page:** 1
**Showing post:** 6

<div class="post-metadata">

### Author: ![sb56637](https://avatars.discourse-cdn.com/v4/letter/s/ea5d25/32.png) [@sb56637](https://meta.discourse.org/u/sb56637)
#### Post date: [27.Октябрь.2025 19:49:10 UTC](https://meta.discourse.org/t/how-to-block-an-ip-range-screened-ips-not-being-blocked/386851/6 "2025-10-27T19:49:10Z")

</div>

Чтобы ещё больше усложнить ситуацию, `ufw` / nftables на хост-сервере, похоже, не блокирует соединения так, как ожидалось, внутри Docker:

> [@Will UFW limit Discourse too?](https://meta.discourse.org/t/will-ufw-limit-discourse-too/231873/12):
>
> This is actually a really good question and one I’m surprised nobody else has yet asked. The answer is complicated, but so far the responses on this topic have unfortunately been dismissive in tone without answering the question. It isn’t per se that Discourse is bypassing ufw, but docker bypasses ufw by adding rules that cause any exposed ports of docker containers to work despite the presence of ufw. What’s going on? Incoming packets destined for a container hit the FORWARD table, not the IN…

---

_[View the full topic](https://meta.discourse.org/t/how-to-block-an-ip-range-screened-ips-not-being-blocked/386851)._
