Getting port-flooded daily, at times that I am supposed to be catching some ZZZ's.
Once the portflooding begins, this IP appears in the email notifications, of which there are plenty:
Code: Select all
tcp6: 19.245.64.24:50654 -> [my VPS IP]:80
I've blocked 19.245.64.24 manually and it's in csf.deny and it makes no difference.
I might have to add that I'm using Cloudflare with mod_cloudflare enabled. The initial email shows the Cloudflare IP, stating that it was blocked with too many connections. Then, subsequent notifications reveal that IP above.
Any help is appreciated!