iptables -S | grep set -A INPUT -p tcp -m set --match-set ipdb7day src -j DROP
So wondering why this is ip, that should have been blocked by iptables was able to get through. Site doesn’t use Cloudflare so the actual ip was seen by the server.
I had assumed (worst word of them all) that since the IP was listed in the 3 day, 7 day and 14 day list, that it was in the list that was downloaded when the cron ran this morning.
However, I neglected to check the test command and sure enough, it wasn’t being blocked. Guessing the ip somehow dropped from the list between github updating the list.
Checking other random IPs from the current 7 day list, they’re all found and being blocked.
Thanks again for your help. You’re a huge asset to the Hestia team and forum.