如何免费拦截所有VPN连接至我的Mindustry游戏服务器?
解决方案:免费阻止VPN连接到Mindustry服务器
针对你的场景,下面是几个免费、无需高频API调用的可行方案,适配你的Ubuntu主机权限和Mindustry插件开发能力:
方案一:本地VPN IP列表+防火墙自动拦截
利用公开维护的免费VPN/代理IP列表,通过脚本自动同步到防火墙规则,完全本地操作,不依赖外部API。
操作步骤:
- 创建定时脚本,负责下载IP列表并更新iptables规则:
#!/bin/bash # 清空旧的VPN专属规则链 iptables -F VPN_BLOCK iptables -X VPN_BLOCK iptables -N VPN_BLOCK # 白名单:允许本地回环和你的管理IP(替换成实际IP) iptables -A VPN_BLOCK -s 127.0.0.1/32 -j ACCEPT iptables -A VPN_BLOCK -s 你的管理IP/32 -j ACCEPT # 下载免费VPN IP列表并批量添加拦截规则(替换为你找到的活跃更新的列表地址) curl -s 你的免费VPN列表地址 | while read ip; do if [[ ! -z "$ip" && ! "$ip" =~ ^# ]]; then iptables -A VPN_BLOCK -s $ip -j DROP fi done # 将规则绑定到Mindustry游戏端口(假设是6567,改成你实际用的端口) iptables -A INPUT -p tcp --dport 6567 -j VPN_BLOCK iptables -A INPUT -p udp --dport 6567 -j VPN_BLOCK # 保存规则,确保重启后生效 iptables-save > /etc/iptables/rules.v4 - 给脚本加执行权限:
chmod +x /root/update_vpn_firewall.sh - 设置crontab每日自动更新(比如凌晨1点):
crontab -e # 添加一行 0 1 * * * /root/update_vpn_firewall.sh
注意事项:
- 优先选更新频繁的开源VPN列表,避免规则失效
- 白名单一定要加,防止自己或管理员被误封
方案二:Mindustry插件本地IP检测
利用Mindustry的插件机制,在玩家连接时直接校验IP是否在本地VPN列表中,直接拒绝违规连接。
核心思路:
- 下载免费的VPN CIDR网段列表,打包到插件资源里,或定期从本地文件读取
- 监听玩家连接事件,提取IP后对比网段,违规则踢人
代码片段(Java):
import mindustry.game.EventType; import mindustry.mod.Plugin; import java.io.BufferedReader; import java.io.InputStreamReader; import java.net.InetAddress; import java.util.HashSet; import java.util.Set; import org.apache.commons.net.util.SubnetUtils; public class AntiVPNPlugin extends Plugin { private final Set<SubnetUtils.SubnetInfo> vpnSubnets = new HashSet<>(); @Override public void init() { // 加载插件资源中的VPN网段列表 try (BufferedReader reader = new BufferedReader( new InputStreamReader(getClass().getResourceAsStream("/vpn_cidrs.txt")))) { String line; while ((line = reader.readLine()) != null) { line = line.trim(); if (!line.isEmpty() && !line.startsWith("#")) { vpnSubnets.add(new SubnetUtils(line).getInfo()); } } } catch (Exception e) { e.printStackTrace(); } // 监听玩家连接事件,拦截VPN Events.on(EventType.PlayerConnect.class, event -> { // 从玩家地址中提取IP(格式是IP:端口) String ipStr = event.player.address().split(":")[0]; try { InetAddress ip = InetAddress.getByName(ipStr); for (SubnetUtils.SubnetInfo subnet : vpnSubnets) { if (subnet.isInRange(ip.getHostAddress())) { event.player.kick("VPN连接被禁止"); break; } } } catch (Exception ignored) { // 忽略IP解析失败的情况 } }); } }
操作提示:
- 把下载的VPN CIDR列表保存为
vpn_cidrs.txt,放到插件的resources目录 - 插件需要引入
commons-net依赖处理CIDR网段判断,可在build.gradle中添加依赖 - 编译后把插件jar包放到Mindustry服务器的mods目录即可
方案三:基于ASN的IP拦截(免费本地库)
多数VPN使用数据中心IP,可通过IP的ASN(自治系统号)判断归属,用MaxMind免费的GeoLite2 ASN数据库实现本地查询。
操作步骤:
- 去MaxMind官网注册免费账号,获取GeoLite2 ASN数据库的下载权限,下载数据库文件到服务器(比如
/usr/local/share/GeoLite2-ASN.mmdb) - 写脚本每月自动更新数据库(加入crontab)
- 在Mindustry插件中查询IP的ASN,拦截已知VPN/数据中心的ASN:
import com.maxmind.geoip2.DatabaseReader; import com.maxmind.geoip2.model.AsnResponse; import java.io.File; import java.net.InetAddress; import java.util.Set; public class AntiVPNPlugin extends Plugin { private DatabaseReader asnReader; // 示例:常见数据中心/VPN的ASN,可自行补充 private final Set<Long> blockedAsns = Set.of(13335, 16509, 20473); @Override public void init() { try { asnReader = new DatabaseReader.Builder( new File("/usr/local/share/GeoLite2-ASN.mmdb")).build(); } catch (Exception e) { e.printStackTrace(); } Events.on(EventType.PlayerConnect.class, event -> { String ipStr = event.player.address().split(":")[0]; try { AsnResponse response = asnReader.asn(InetAddress.getByName(ipStr)); long asn = response.getAutonomousSystemNumber(); if (blockedAsns.contains(asn)) { event.player.kick("VPN/数据中心IP被禁止"); } } catch (Exception ignored) {} }); } }
注意事项:
- GeoLite2数据库每月更新一次,需定时同步
- 可通过公开资料收集更多VPN运营商的ASN,或直接拦截大型云服务商的ASN(适合非云主机的游戏服务器)
内容的提问来源于stack exchange,提问作者user20695421
相关产品推荐
相关产品推荐

