I am running the latest version of ConfigServer Firewall on Centos 6.
I have a TeamSpeak3 server running also on 185.13.225.90:9987.
In the configuration file i added all TCP and UDP ports used by TeamSpeak3.
Some people can connect with my server without a problem, others cannot connect and are getting a connection error.
After this, they are also not able to acces my website for a short amount of time.
It's like they are being temp banned by ConfigServer after connecting to TS3.
When i look into the log file lfd.log i see this:
Code: Select all
Jun 11 00:04:52 Cloudbox15475 lfd[14270]: *Suspicious Process* PID:30532 PPID:30532 User:teamspeak3 Uptime:691353 secs EXE:/ts3server/teamspeak3/ts3server_linux_amd64 CMD:./ts3server_linux_amd64
Jun 11 00:04:52 Cloudbox15475 lfd[14270]: *User Processing* PID:30532 Kill:0 User:teamspeak3 VM:1026(MB) EXE:/ts3server/teamspeak3/ts3server_linux_amd64 CMD:./ts3server_linux_amd64
Jun 11 00:04:52 Cloudbox15475 lfd[14270]: *User Processing* PID:30532 Kill:0 User:teamspeak3 Time:691353 EXE:/ts3server/teamspeak3/ts3server_linux_amd64 CMD:./ts3server_linux_amd64
Jun 11 00:13:48 Cloudbox15475 lfd[15540]: *Port Scan* detected from 92.70.80.73 (NL/Netherlands/static). 11 hits in the last 235 seconds - *Blocked in csf* for 3600 secs [PS_LIMIT]
Greets,
Mark