SetNet.BanList 1.2.0

dotnet add package SetNet.BanList --version 1.2.0
                    
NuGet\Install-Package SetNet.BanList -Version 1.2.0
                    
This command is intended to be used within the Package Manager Console in Visual Studio, as it uses the NuGet module's version of Install-Package.
<PackageReference Include="SetNet.BanList" Version="1.2.0" />
                    
For projects that support PackageReference, copy this XML node into the project file to reference the package.
<PackageVersion Include="SetNet.BanList" Version="1.2.0" />
                    
Directory.Packages.props
<PackageReference Include="SetNet.BanList" />
                    
Project file
For projects that support Central Package Management (CPM), copy this XML node into the solution Directory.Packages.props file to version the package.
paket add SetNet.BanList --version 1.2.0
                    
#r "nuget: SetNet.BanList, 1.2.0"
                    
#r directive can be used in F# Interactive and Polyglot Notebooks. Copy this into the interactive tool or source code of the script to reference the package.
#:package SetNet.BanList@1.2.0
                    
#:package directive can be used in C# file-based apps starting in .NET 10 preview 4. Copy this into a .cs file before any lines of code to reference the package.
#addin nuget:?package=SetNet.BanList&version=1.2.0
                    
Install as a Cake Addin
#tool nuget:?package=SetNet.BanList&version=1.2.0
                    
Install as a Cake Tool

<p align="center"> <img src="https://raw.githubusercontent.com/Povstalez/SetNet/master/assets/icon.png" alt="SetNet" width="96"> </p>

SetNet.BanList

Ban enforcement for SetNet.

Drop all traffic from banned peers and kick matching live connections instantly. Ban by IP address (the default) or by a custom key such as the authenticated account id. Bans can be permanent or timed. The store is pluggable — in-process by default, or supply a Redis/DB implementation to share bans across nodes and survive restarts. Added by composition (no base class): the enforcement gate is chained onto the server's existing InboundAuthorizer, so it stacks cleanly with SetNet.Auth and SetNet.RateLimit.

Install

dotnet add package SetNet
dotnet add package SetNet.BanList

Usage

Ban by IP (default)

var bans = server.UseBanList();

bans.Ban("203.0.113.7");                                 // permanent — kicks live peers + blocks reconnects
bans.Ban("203.0.113.7", DateTime.UtcNow.AddHours(1));    // timed ban (auto-expires)
bans.Unban("203.0.113.7");

if (bans.IsBanned("203.0.113.7")) { /* ... */ }

Ban does two things: it records the ban in the store, and it immediately kicks every currently-connected peer whose key matches.

Ban by account id

Pair with SetNet.Auth and key bans on the authenticated identity instead of the raw IP:

var bans = server.UseBanList(peer => AccountOf(peer));   // your peer → account-id selector
bans.Ban("account-123");

Cross-node / persistent bans

Pass your own IBanStore (must be thread-safe) so bans are shared and outlive a restart:

var bans = server.UseBanList(new RedisBanStore());               // IP-keyed, shared store
var bans = server.UseBanList(peer => AccountOf(peer), redisStore); // account-keyed, shared store

API

server.UseBanList(...)BanList

Overload Ban key
UseBanList(IBanStore? store = null) peer's remote IP (falls back to the peer's connection id if no RemoteEndPoint)
UseBanList(Func<BasePeer,string> keySelector, IBanStore? store = null) whatever your selector returns (e.g. account id)

BanList

Member Purpose
void Ban(string key, DateTime? untilUtc = null) ban a key (permanent when untilUtc is null) and kick matching live peers
void Unban(string key) lift a ban
bool IsBanned(string key) current ban state (expired timed bans read as not-banned)
void Kick(BasePeer peer) force-disconnect one peer

IBanStorebool IsBanned(string), void Ban(string, DateTime?), void Unban(string). Default implementation MemoryBanStore is an in-process dictionary that lazily evicts expired timed bans.

Notes

  • By-IP needs a real endpoint. The default keys on peer.RemoteEndPoint?.Address; transports that don't expose one (e.g. the in-memory test transport) fall back to the connection id, which is per-connection — so an IP ban won't survive reconnect there. On real TCP/UDP/WebSocket transports the IP is available.
  • The default store is per-process. Bans vanish on restart and aren't shared between server nodes — supply a Redis/DB IBanStore for a cluster or for durability.
  • Composes, doesn't replace. The gate chains onto any prior InboundAuthorizer, so install order with Auth/RateLimit doesn't matter — all gates must pass for a frame to be delivered.
  • IPv4/IPv6 and shared NATs. IP bans hit everyone behind the same NAT/proxy; prefer account-keyed bans once you have authentication.

Documentation & source

License

MIT

Product Compatible and additional computed target framework versions.
.NET net5.0 was computed.  net5.0-windows was computed.  net6.0 was computed.  net6.0-android was computed.  net6.0-ios was computed.  net6.0-maccatalyst was computed.  net6.0-macos was computed.  net6.0-tvos was computed.  net6.0-windows was computed.  net7.0 was computed.  net7.0-android was computed.  net7.0-ios was computed.  net7.0-maccatalyst was computed.  net7.0-macos was computed.  net7.0-tvos was computed.  net7.0-windows was computed.  net8.0 was computed.  net8.0-android was computed.  net8.0-browser was computed.  net8.0-ios was computed.  net8.0-maccatalyst was computed.  net8.0-macos was computed.  net8.0-tvos was computed.  net8.0-windows was computed.  net9.0 was computed.  net9.0-android was computed.  net9.0-browser was computed.  net9.0-ios was computed.  net9.0-maccatalyst was computed.  net9.0-macos was computed.  net9.0-tvos was computed.  net9.0-windows was computed.  net10.0 was computed.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
.NET Core netcoreapp3.0 was computed.  netcoreapp3.1 was computed. 
.NET Standard netstandard2.1 is compatible. 
MonoAndroid monoandroid was computed. 
MonoMac monomac was computed. 
MonoTouch monotouch was computed. 
Tizen tizen60 was computed. 
Xamarin.iOS xamarinios was computed. 
Xamarin.Mac xamarinmac was computed. 
Xamarin.TVOS xamarintvos was computed. 
Xamarin.WatchOS xamarinwatchos was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.
  • .NETStandard 2.1

NuGet packages (2)

Showing the top 2 NuGet packages that depend on SetNet.BanList:

Package Downloads
SetNet.DdosGuard

Connection-flood protection for SetNet: counts new connections per source IP over a sliding window and temporarily auto-bans an IP that opens too many too fast (dropping its traffic and kicking its peers via SetNet.BanList). server.UseDdosGuard(). Depends on SetNet + SetNet.BanList.

SetNet.Redis

Redis backplane for SetNet: shared, restart-surviving implementations of ISessionStore (Auth), IBanStore (BanList) and IRoomStore (Rooms/Matchmaking) so sessions, bans and room codes work across a cluster of server nodes. Depends on SetNet.Auth + SetNet.Rooms + SetNet.BanList + StackExchange.Redis.

GitHub repositories

This package is not used by any popular GitHub repositories.

Version Downloads Last Updated
1.2.0 107 8/5/2026
1.1.0 201 7/2/2026