Managed to set up a custom 'Failed SASL login' IP block and it is showing a temporary block as expected.
I think I have finally got it figured out. Now I just need to monitor my logs and the CFS/LFD blocks to ensure its working as expected.
Search found 10 matches
- 08 Sep 2020, 05:04
- Forum: General Discussion (csf)
- Topic: LFD log does not show any problem IP info
- Replies: 3
- Views: 2403
- 07 Sep 2020, 16:28
- Forum: General Discussion (csf)
- Topic: LFD log does not show any problem IP info
- Replies: 3
- Views: 2403
Re: LFD log does not show any problem IP info
I believe that my LFD issue (Log not displaying any blocks) was due to a change in the log files used for SMTP and ProFTP. Both had been set for var/logs/messages but the proper log files were var/log/maillog (SMTP) and var/log/secure (ProFTP) not sure if they had never been set correctly or if it w...
- 06 Sep 2020, 19:39
- Forum: General Discussion (csf)
- Topic: LFD log does not show any problem IP info
- Replies: 3
- Views: 2403
Re: LFD log does not show any problem IP info
After making quite a few changes in the CSF/LFD config I appear to be having some of the SMTP login failure IPs being tagged and placed in the Deny file. These are permanent blocks but I still can't see any temp blocks happening in the log nor do I see any file in CSF that holds the temporary blocke...
- 06 Sep 2020, 19:09
- Forum: General Discussion (csf)
- Topic: How to Disable Temporary SSHD login alert mail
- Replies: 3
- Views: 3003
Re: How to Disable Temporary SSHD login alert mail
You can use this and set it to not send emails but you won't get any blocked alerts # Send an email alert if an IP address is blocked by one of the [*] triggers LF_EMAIL_ALERT = "1" You could also create a special email account just to receive the LFD alerts and redirect the emails there. ...
- 03 Sep 2020, 06:53
- Forum: General Discussion (csf)
- Topic: Sudden Failed IMAP Logins
- Replies: 1
- Views: 1487
Re: Sudden Failed IMAP Logins
Failed Imap authorization would be a bad password or username using his real ip address so maybe an incorrect setting in a mail client that attempts to connect every few minutes?
If its an inability to connect after so many tries in a set period of time Login Tracking can do that.
If its an inability to connect after so many tries in a set period of time Login Tracking can do that.
- 03 Sep 2020, 01:09
- Forum: General Discussion (csf)
- Topic: SSH Login Problem with CSF because of Dynamic IP
- Replies: 1
- Views: 1572
Re: SSH Login Problem with CSF because of Dynamic IP
Not sure if this is what you are asking. Can't you just add Port 22 to your allowed list in the csf.conf file? I assume you are talking about the IP address (changing) on the computer you use to access your server and not the Server's IP address. # Allow incoming TCP ports TCP_IN = "20,21,22,25...
- 02 Sep 2020, 19:32
- Forum: General Discussion (csf)
- Topic: Suspicious Process. Can't stop the notifications
- Replies: 1
- Views: 2354
Re: Suspicious Process. Can't stop the notifications
I don't know if csf -ra restarts LFD as well.
Did you try restarting LFD after making your changes to pignore just in case?
I read somewhere that LFD had to be restarted as well for it to work properly. Might be worth a try.
Did you try restarting LFD after making your changes to pignore just in case?
I read somewhere that LFD had to be restarted as well for it to work properly. Might be worth a try.
- 02 Sep 2020, 19:20
- Forum: General Discussion (csf)
- Topic: How to Disable Temporary SSHD login alert mail
- Replies: 3
- Views: 3003
Re: Disable Temporary SSHD login alert mail
Do you mean this?
# Send an email alert if anyone logs in successfully using SSH
#
# SECURITY NOTE: This option is affected by the RESTRICT_SYSLOG option. Read
# this file about RESTRICT_SYSLOG before enabling this option:
LF_SSH_EMAIL_ALERT = "1"
# Send an email alert if anyone logs in successfully using SSH
#
# SECURITY NOTE: This option is affected by the RESTRICT_SYSLOG option. Read
# this file about RESTRICT_SYSLOG before enabling this option:
LF_SSH_EMAIL_ALERT = "1"
- 02 Sep 2020, 18:07
- Forum: General Discussion (csf)
- Topic: LFD log does not show any problem IP info
- Replies: 3
- Views: 2403
LFD log does not show any problem IP info
I am trying to figure out why the LFD is not showing or catching any ips that have been failing authentication. I have had a lot of unauthorized ips trying to log in to mail, ftp, ssh etc but they never show up in the LFD log nor do they appear in the CSF deny list. I can manually add them to the de...
- 31 Aug 2020, 01:42
- Forum: General Discussion (csf)
- Topic: log error - Deleted -
- Replies: 0
- Views: 2041
log error - Deleted -
---Deleted---