Page 1 of 1

CSF PS_ Failure?

Posted: 13 Apr 2009, 02:26
by yah0m
PS_INTERVAL = "300"
PS_LIMIT = "7"
PS_PORTS = "0:65535"
PS_PERMANENT = "0"
PS_BLOCK_TIME = "3600"

yes, /var/log/messages is getting flooded by SYNFLOOD but none of the IPs are getting pulled into csf.tempban

Posted: 15 Apr 2009, 10:07
by chirpy
Did you make sure that you restarted csf and lfd after making any config changes? If so, are you seeing more than 7 hits within the 300 second interval? If so, paste the iptables log section showing these and I'll see if I can recreate the problem.

Posted: 19 Apr 2009, 01:16
by yah0m
Yeah, I'm sure everything is right. I'm DDoS'ed 24/7 so I've had a lot of time to toy with it. How and where would I pull the log file?

Posted: 25 Apr 2009, 10:40
by chirpy
The log file is wherever you have configured IPTABLES_LOG to, usually /var/log/messages. You can also view the last 100 entries through the csf UI.