Page 1 of 1

Complete VPS down

Posted: 06 Nov 2015, 16:02
by john01
Complete VPS down

After installing Config Server Firewall, all settings are properly checked before I Config Server Firewall puts online.

Config Server Firewall worked well, and blocked several IP addresses. However, several IP addresses, he did not block, I have also used the following setting as listed below.

After adding the following countries and IN BR went the entire VPS Server Down.

Can not log in via port 12.055.34.24:2222
Access via mRemoteNG
Access via FTP
################################################## #############################
# SECTION: Country Code Lists and Settings
################################################## #############################
# Country Code CIDR to allow / deny. In the Following two options you can allow
# Or deny whole country CIDR ranges. The CIDR blocks are generated from the
# Maxmind GeoLite Country database http://www.maxmind.com/app/geolitecountry
# Entirely and relies on That service being available
#
# Specify the the two-letter ISO country code (s). The iptables rules are for
# Incoming connections only
#
# You shouldering consider using LF_IPSET When using any of the Following options
#
# WARNING: These lists are never 100% accurate and some ISPs (eg, AOL) use
# Non-geographic IP address designations for Their Clients
#
# WARNING: Some of the CIDR lists are huge and each one requires a rule within
# The incoming iptables chain. This can result in significant performance
# Overheads and could render the server inaccessible in some circumstances. For
# This reason (amongst others) we do not recommend usingthese options
#
# WARNING: Due to the resource constraints on VPS servers this feature shouldering
# Not be used on Such systems Unless you choose very small CC zones
#
# WARNING: CC_ALLOW Allows access through all ports in the firewall. For this
# Reason CC_ALLOW HAS probably very limited use and is CC_ALLOW_FILTER
# Preferred
#
# Each option is a comma separated list of CC's, eg "US, UK, DE"
CC_DENY = "CN, UA, PL, RU, KP, CZ, IN, SD"
CC_ALLOW = ""

_________________________________________________________

# This option denies access from the Following countries to specific ports
# Listed in CC_DENY_PORTS_TCP and CC_DENY_PORTS_UDP
#
# Note: The rules for this feature are inserted after the allow and deny
# Still rules to allow allo wing or IP addresses
#
# Each option is a comma separated list of CC's, eg "US, UK, DE"
CC_DENY_PORTS = "CN, UA, PL, RU, KP, CZ, IN, SD"

Re: Complete VPS down

Posted: 07 Nov 2015, 10:32
by john01
The command "stop /etc/init.d/csf" I can turn off the service and again I seem to be able to login via SSH and also access to Direct Admin seems to be working again.

I am required to perform a redeploy.
This indicates that the entire VPS server reinstall.

I have to make a proper note on Config Server, the configuration is described very poor. It is often recommended that where and in which file you should perform an adjustment.

Which I find very regrettable Config Server.