I get this email from my server:
Subject: Cron /usr/sbin/csf -u
Message: csf and lfd have been disabled, use 'csf -e' to enable
I logged in to WHM to enable again all connection become blocked, if I disable via SSH everything works fine.
I can't image what I have to do to work again, should I reinstall csf or how can I find the problem?
I did not changed anything for weeks, csf updated 5...
When CSF blocks an IP, it shows all the information of where and why including the country code. I'm not sure where CSF gets the country code information but why can't you simply block by the country code instead of huge lists of CIDR's? I am able to do this in Modesecurity but I would rather block for the entire server instead of just http.
We are trying to block all incoming IPs and only allow cloudflare IPs. We've whitelisted this in csf.allow we still wanted to check if from CSF side if we can block all other traffic.
I hope you are well. I now manage numerous servers running WHM; and I have lately begun integrating config server security and firewall and login failure daemon to improve the security of these systems. While I have some familiarity with server management; I am new to the more advanced configurations and optimizations that CSF and LFD provide. I am seeking out this informed...
On a machine with CSF (although on others the problem has appeared after writing this ticket)
It has been installed and running for years.
The settings are very restrictive. Only port of entry 53 is open, the rest are not.
Access is only allowed to my ips. One of them dynamic, added to csf.dyndns
Today I couldn't get in. So I logged into the server via KVM (it's a proxmox)
In order to sort (some) compatibility with Docker and CSF we are working on an approach to allow docker to handle its iptables adding a chain on prerouting added in csfpost.sh
The problem is that for this to work we need to store all docker generated chains on each csf restart and reload them in csfpost.sh
For my surprise, csfpre.sh is not executed first on that process. CSF first clears all...
Hi, we do not see any CSF email alerts in the exim_mainlog, and we aren't receiving any either. The server is also running cPanel and WHM. We have taken the following steps to check that everything is set:
Testing = 0 in the configuration
LF_ALERT_TO AND X_ARF_TO are set to the correct email
Alerts are turned on in the configuration
LF_EMAIL_ALERT is set to 1 or true
/etc/aliases root is...
I'm new to firewall/server configurations and I have a PCI scan result saying:
THREAT:
Your firewall policy seems to let TCP packets with a specific source port pass through.
IMPACT:
Some types of requests can pass through the firewall. The port number listed in the results section of this vulnerability report is the source
port that unauthorized users can use to bypass your...
We have the following issues with Almalinux any suggestions?
# perl /usr/local/csf/bin/csftest.pl
Testing ip_tables/iptable_filter...FAILED - Required for csf to function
Testing ipt_LOG...FAILED - Required for csf to function
Testing ipt_multiport/xt_multiport...FAILED - Required for csf to function
Testing ipt_REJECT...FAILED - Required for csf to function
Testing...
First its good to be back, its been since 2014/16 since i was here last, long long time.... I see you have changed support forum structure, looking good :) Hope you are all doing well...
I have a WHM/cPanel VPS that i am setting up with only 1 cPanel account, which is me, noone else will be using the VPS. The only access is root and my account login, SSH and FTP are disabled as is...
How can we disable the passive mode that we had previously enabled as well as activate the SPI that we had disabled.
Thank you very much in advance for your help
Viewing in WHM> ConfigServer Security & Firewall - csf v14.20 and it says enabled and also confirmed in lfd.log but it references mod_cloudflare which is no longer supported, so I'm using mod_remoteip. Is this integration still working? If so, how to verify?
Hi all,
Where does csf keep the list of blocked emails that are associated with IP address?
I remember on one of my previous csf installations I had the ability to see blocked emails and from which IP addresses these emails tried to connect but now I can't find it on this new server.
Hello, every 5 minutes I receive this email. What I can do ? You never did this before and the configuration is the same as when you did it several years ago, I have not modified anything since then
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum