*Port Flood* csf perm ban
Posted: 20 Dec 2021, 19:23
Hello,
I would like to permanently block/ban the ips that csf detects as "port flood" but I cannot. I have very often back attacks of this type:
Dec 17 23:05:15 nsxxxx kernel: [2415976.555544] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1329 PROTO=UDP SPT=59384 DPT=27017 LEN=33
Dec 17 23:05:19 nsxxxxx kernel: [2415980.720442] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1335 PROTO=UDP SPT=59414 DPT=27015 LEN=33
Dec 17 23:05:24 nsxxxxx kernel: [2415984.947282] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1337 PROTO=UDP SPT=59417 DPT=27017 LEN=33
Dec 17 23:05:26 nsxxxxx kernel: [2415988.379278] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=37 TOS=0x00 PREC=0x00 TTL=118 ID=1345 PROTO=UDP SPT=51822 DPT=27015 LEN=17
Dec 17 23:05:26 nsxxxxx kernel: [2415988.381667] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=37 TOS=0x00 PREC=0x00 TTL=118 ID=1344 PROTO=UDP SPT=51821 DPT=27015 LEN=17
Dec 17 23:05:29 nsxxxxx kernel: [2415990.722440] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1348 PROTO=UDP SPT=51824 DPT=27015 LEN=33
and csf does not block ip.
I wanted to add fail2ban to csf but apparently no working or bug... Maybe another csf module is needed?
Thank you,
I would like to permanently block/ban the ips that csf detects as "port flood" but I cannot. I have very often back attacks of this type:
Dec 17 23:05:15 nsxxxx kernel: [2415976.555544] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1329 PROTO=UDP SPT=59384 DPT=27017 LEN=33
Dec 17 23:05:19 nsxxxxx kernel: [2415980.720442] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1335 PROTO=UDP SPT=59414 DPT=27015 LEN=33
Dec 17 23:05:24 nsxxxxx kernel: [2415984.947282] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1337 PROTO=UDP SPT=59417 DPT=27017 LEN=33
Dec 17 23:05:26 nsxxxxx kernel: [2415988.379278] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=37 TOS=0x00 PREC=0x00 TTL=118 ID=1345 PROTO=UDP SPT=51822 DPT=27015 LEN=17
Dec 17 23:05:26 nsxxxxx kernel: [2415988.381667] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=37 TOS=0x00 PREC=0x00 TTL=118 ID=1344 PROTO=UDP SPT=51821 DPT=27015 LEN=17
Dec 17 23:05:29 nsxxxxx kernel: [2415990.722440] Firewall: *Port Flood* IN=eno1 OUT= MAC=1c:b7:2c:ae:da:45:00:ff:ff:ff:ff:fb:08:00 SRC=ip.ip.ip.ip DST=ip.ip.ip.ip LEN=53 TOS=0x00 PREC=0x00 TTL=118 ID=1348 PROTO=UDP SPT=51824 DPT=27015 LEN=33
and csf does not block ip.
I wanted to add fail2ban to csf but apparently no working or bug... Maybe another csf module is needed?
Thank you,