CSF Blocking Legitimate SSH traffic

Post Reply
blasto33
Junior Member
Posts: 1
Joined: 15 Jan 2014, 21:10

CSF Blocking Legitimate SSH traffic

Post by blasto33 »

I have a developer working on a project on my server. He only connected to port 22 and 80 and it would block him. I have also seen this happen to http traffic. I have turned it off for now, as it blocks legitimate traffic. Is this normal?


Block:

Temporary Blocks: IP:112.110.51.230 Port: Dir:in TTL:3600 (lfd - *Port Scan* detected from 112.110.51.230 (IN/India/-). 11 hits in the last 285 seconds)
Adding 112.110.51.230 to csf.allow and iptables ACCEPT...
ForumAdmin
Moderator
Posts: 1524
Joined: 01 Oct 2008, 09:24

Re: CSF Blocking Legitimate SSH traffic

Post by ForumAdmin »

You would have to look at either your server message log or the email sent to the root forwarder for the iptables log lines that lfd detected the port scan for to determine why the IP was blocked.
Post Reply