Mod_security CSF
Posted: 12 Jan 2022, 01:18
Hello,
This topic has been mentioned already. I have read all the relative posts, I think and cannot find an answer.
We are running centos 7.9, mod_security 3, CSF rules and mod_lsapi. We do see that mod_security is correctly identifying attacks in the cPanel tools. When we look in our CSF logs, we see only about a third of the IP's are being blocked.
Saw mention of the need to create a regex. No clue how to do that. We found some regex here to block mod_ IP's but they dont work. The LF settings are set to "1" to permanently block the IP.
Does anyone have a regex that will block all mod_security IP addresses? Or have a clue what we can do to fix this? We would like all identified attacks to be blocked, not just some of them.
Is it possible to get support from config? How do we go about that?
thanks in advance
Jerry
This topic has been mentioned already. I have read all the relative posts, I think and cannot find an answer.
We are running centos 7.9, mod_security 3, CSF rules and mod_lsapi. We do see that mod_security is correctly identifying attacks in the cPanel tools. When we look in our CSF logs, we see only about a third of the IP's are being blocked.
Saw mention of the need to create a regex. No clue how to do that. We found some regex here to block mod_ IP's but they dont work. The LF settings are set to "1" to permanently block the IP.
Does anyone have a regex that will block all mod_security IP addresses? Or have a clue what we can do to fix this? We would like all identified attacks to be blocked, not just some of them.
Is it possible to get support from config? How do we go about that?
thanks in advance
Jerry