IP Reputation and Network Intelligence Monitoring
2.4K
IP Reputation and Network Intelligence Monitoring
IPXA is a high-performance, private-by-design platform for threat intelligence aggregation. It provides instant IP reputation queries, GeoIP data, and integration with 15+ Real-time Blackhole Lists (RBLs), all running entirely on your own infrastructure.
Instantly visualize the origin and risk score of any IP address with our premium web dashboard.
Multi-workspace environment for isolated security configurations.
The Admin Interface (accessible on port 5001 at the /admin context) features a secure dashboard for managing workspaces, RBL threat lists, and monitoring parameters. It includes a secure session management login system and a one-click logout.
You can configure the access credentials using the following environment variables:
admin@local)admin)
Manage your workspaces, feeds, and configurations dynamically through a premium, dark-mode administrative dashboard.
IPXA is distributed as a lightweight Docker image.
volumes:
data:
services:
ipxa:
image: liberatti/ipxa:latest
environment:
- API_KEY=dev
# - SECURITY_ENABLED=false
# - IPINFO_TOKEN=
# - IBLOCKLIST_USERNAME=
# - IBLOCKLIST_PASSWORD=
# - MAXMIND_ACCOUNT_ID=
# - MAXMIND_LICENSE_KEY=
volumes:
- data:/data
ports:
- "5001:5000"
deploy:
resources:
limits:
memory: 256M
portal:
image: liberatti/ipxa-portal:latest
environment:
- IPXA_API_KEY=dev
- IPXA_API_URL=http://ipxa:5000
ports:
- "5000:5000"
deploy:
resources:
limits:
memory: 64M
IPXA provides native, high-performance middleware hooks for popular web servers, allowing you to block malicious traffic at the edge. These hooks support standardized JSON error responses with unique request_id tracking for enhanced observability.
mod_lua)Integrate IPXA directly into your Apache configuration using mod_lua to evaluate IPs on the fly.
Quick Setup:
mod_lua and lua-socket (e.g., yum install httpd mod_lua lua-socket).hooks/httpd/lua/*.lua to your Apache lua directory (e.g., /etc/httpd/lua/)./etc/httpd/lua/config.lua with your IPXA API URL and settings.VirtualHost:
<VirtualHost *:80>
ServerName example.com
DocumentRoot /var/www/html
# IPXA Access Control
LuaHookAccessChecker /etc/httpd/lua/ipxa.lua ip_info_check
# IPXA JSON Error Handler
Alias /errors /etc/httpd/lua/errors.lua
<Location /errors>
SetHandler lua-script
</Location>
ErrorDocument 403 /errors
</VirtualHost>
(See hooks/httpd/README.md for full details).
Leverage the power of Lua in Nginx via OpenResty for ultra-low latency IP checking, complete with local caching.
Quick Setup:
lua-resty-http package (via luarocks).hooks/openresty/lua/ to your OpenResty lualib path (e.g., /usr/local/openresty/lualib/ipxa/).config.lua with your IPXA API URL and blocklist settings.nginx.conf:
http {
# ...
lua_package_path "/usr/local/openresty/lualib/ipxa/?.lua;;";
lua_shared_dict ip_cache 10m; # Required for caching
server {
# ...
error_page 403 /lua-error;
location / {
access_by_lua_file /usr/local/openresty/lualib/ipxa/ip_info_check.lua;
}
location = /lua-error {
internal;
content_by_lua_file /usr/local/openresty/lualib/ipxa/errors.lua;
}
}
}
(Check hooks/openresty/nginx.conf and hooks/openresty/Dockerfile for working examples).
When a request is blocked, the hooks return a machine-readable JSON response instead of default HTML error pages. This ensures consistent error handling for both browsers and API clients.
Example Blocked Response:
{
"error": "Forbidden",
"status": 403,
"request_id": "b10ed3a6f76ad62a75a956ce3e922336",
"message": "ipxa [block/risk-score]: 172.20.0.1 risk_score=14"
}
GET /api/ip/info/{address}
Returns comprehensive GeoIP, ASN, and reputation data.
Example Response:
{
"ip": {
"address": "14.152.94.1",
"broadcast": "14.152.95.255",
"network": "14.152.80.0",
"prefix": 20,
"version": 4
},
"location": {
"continent": "Asia",
"country_code": "CN",
"country_name": "China"
},
"organization": {
"asn_description": "",
"asn_name": "CT-DONGGUAN-IDC CHINANET Guangdong province network",
"asn_number": 134763
},
"security": {
"reasons": [
"rbl:firehol_level1"
],
"risk_score": 0
}
}
GET /api/ip/check/{address}
Simplified response focused on reputation and risk assessment.
Example Response:
{
"ip": "14.152.94.1",
"risk_score": 0,
"reasons": ["rbl:firehol_level1"]
}
GET /api/ip/quick/{address}
Optimized for firewalls and middleware. Returns risk score in body and x-risk-score header.
Example Response:
{
"risk_score": 9
}
IPXA includes an api.rest file for rapid API testing.
api.rest and click Send Request above any endpoint.While advanced users can still add JSON files in config/, IPXA now features a complete Admin Panel to manage feeds dynamically through the UI.
| Field | Description |
|---|---|
name | Human-friendly identifier for the feed |
slug | Unique internal identifier |
type | reputation (for blocking) or bypass (for allowlisting) |
source | Public URL for download (CIDR or IP list) |
format | cdir_text (plain text) or cdir_gz (compressed) |
risk_score | Weight of this feed in the final decision (0-10) |
Includes a pre-configured library of industry-standard feeds:
Disclaimer of Warranty: This software is provided "AS IS", without warranty of any kind, express or implied. The author(s) and contributor(s) shall not be liable for any claim, damages, or other liability, whether in an action of contract, tort, or otherwise, arising from, out of, or in connection with the software or the use or other dealings in the software.
Use at Your Own Risk: You are solely responsible for any decisions made or actions taken based on the data provided by IPXA. The software involves security-related functions; its misconfiguration or misuse could lead to service disruption or security gaps.
This project is licensed under the Apache License 2.0. See the LICENSE file for details.
Content type
Image
Digest
sha256:3928f0539…
Size
161.5 MB
Last updated
20 days ago
docker pull liberatti/ipxa:v1.0.9-hotfix-20260630214527