How to block an IP range? "Screened IPs" not being blocked

And to further complicate things, ufw / nftables on the host server apparently doesn’t block things as expected inside Docker:

1 Like