Block specific port even to global allow IP?
Posted: 18 Mar 2013, 10:44
I am failing PCI because my database port is open. Thing is its not, its blocked by CSF. But in order for the PCI scans to run OK and do their checks I have to add them to the IP allow list. So THEY can see the port open, even though no one else can, and fail us!
So therefore I would like to know if its possible to keep them (and other IPs) in the allow list, but still block the database port (and any other port I think I may want to block even to the allow list).
We are also using the GLOBAL_ALLOW to retrieve these IP addresses from a remote file, because we have many servers to add allow IPs for.
Thanks a lot
So therefore I would like to know if its possible to keep them (and other IPs) in the allow list, but still block the database port (and any other port I think I may want to block even to the allow list).
We are also using the GLOBAL_ALLOW to retrieve these IP addresses from a remote file, because we have many servers to add allow IPs for.
Thanks a lot