Csf Block my whitlelist ip

Post Reply
Test blogger22
Junior Member
Posts: 5
Joined: 18 Dec 2022, 08:43

Csf Block my whitlelist ip

Post by Test blogger22 »

Hi
I have a very bad problem , i put some ip in csf.allow and even in csf.ignore but they still blocked by firewwall.
can anyone help me?
Sergio
Junior Member
Posts: 1712
Joined: 12 Dec 2006, 14:56

Re: Csf Block my whitlelist ip

Post by Sergio »

Please, give an example of the message that the IP got when blocked.

Sergio
Test blogger22
Junior Member
Posts: 5
Joined: 18 Dec 2022, 08:43

Re: Csf Block my whitlelist ip

Post by Test blogger22 »

it says" site took too long to respond"
i try to connect to my http port of my server.
Sergio
Junior Member
Posts: 1712
Joined: 12 Dec 2006, 14:56

Re: Csf Block my whitlelist ip

Post by Sergio »

Start checking that your port 80 is opened in CSF TCP IN 4/6 and TCP OUT 4/6
and
that your port 443 is opened in CSF TCP IN 4/6, TCP OUT 4/6 and in UDP IN/OUT 4/6.
Test blogger22
Junior Member
Posts: 5
Joined: 18 Dec 2022, 08:43

Re: Csf Block my whitlelist ip

Post by Test blogger22 »

yest it is open , but i cannot reach to it when i turn csf on.
even i put ip in csf.ignore but is still block.
Sergio
Junior Member
Posts: 1712
Joined: 12 Dec 2006, 14:56

Re: Csf Block my whitlelist ip

Post by Sergio »

Have you checked that the IP that you are white listening is not in an RBL?
Test blogger22
Junior Member
Posts: 5
Joined: 18 Dec 2022, 08:43

Re: Csf Block my whitlelist ip

Post by Test blogger22 »

sorry , what is RBL?
Test blogger22
Junior Member
Posts: 5
Joined: 18 Dec 2022, 08:43

Re: Csf Block my whitlelist ip

Post by Test blogger22 »

Thanks for help
and yes i checked my ip isn't in RBL.
Sergio wrote: 26 Jun 2024, 15:52 Have you checked that the IP that you are white listening is not in an RBL?
Sergio
Junior Member
Posts: 1712
Joined: 12 Dec 2006, 14:56

Re: Csf Block my whitlelist ip

Post by Sergio »

You have to check a few things.
- Does cPhulk is running in your server? If yes, then check if the IP is not being block by cPhulk. If it is, then add your IP on the whitelist in cPhulk.
- Have you tried to add your IP on /etc/csf/csf.ignore ?
If not then, do what the readme on file suggest:

# The following IP addresses will be ignored by all lfd checks
# One IP address per line
# CIDR addressing allowed with a quaded IP (e.g. 192.168.254.0/24)
# Only list IP addresses, not domain names (they will be ignored)

Regards,
Sergio
Post Reply