Connection Tracking does not work!
Posted: 25 Feb 2014, 16:47
Hello,
I have updated csf to 4.46.
I found that Connection Tracking does not work although those ips are noted in tempip file.
For a very strick connection tracking, I have the following:
CT_LIMIT = 2
CT_INTERVAL = 200
CT_PORTS = 25,137,445
On the above ports there is constant spamming. The third connection should be imposing a temporary block (perm=0). This occurs very rarely although there are several ips that gets registered by spamdyke and are searchable in maillog. They are connectted multiple times and, thus, should be blocked by csf.
Other than this, most of the configuration is working fine.
I have port scan values, as well as all other values, setup higher. hence CT_LIMIT must be activated and that connection must be blocked. Unfortunately, this does not work anymore after the update.
Any suggestions for further infos to be given by me?
I have updated csf to 4.46.
I found that Connection Tracking does not work although those ips are noted in tempip file.
For a very strick connection tracking, I have the following:
CT_LIMIT = 2
CT_INTERVAL = 200
CT_PORTS = 25,137,445
On the above ports there is constant spamming. The third connection should be imposing a temporary block (perm=0). This occurs very rarely although there are several ips that gets registered by spamdyke and are searchable in maillog. They are connectted multiple times and, thus, should be blocked by csf.
Other than this, most of the configuration is working fine.
I have port scan values, as well as all other values, setup higher. hence CT_LIMIT must be activated and that connection must be blocked. Unfortunately, this does not work anymore after the update.
Any suggestions for further infos to be given by me?