Welcome to the JaguarPC Community
JaguarPC
Sales: (888) 338-5261
Support: (888)-551-3050
Page 2 of 2 FirstFirst 12
Results 16 to 25 of 25

This is a discussion on Security - Server in the General Hosting and Network Support forum
Originally Posted by gohighvoltage Question, "thisisit" has a BFD rules for Jag servers, Should I need this, since I have CSF installed and running? NO ...

  1. #16
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    Quote Originally Posted by gohighvoltage View Post
    Question, "thisisit" has a BFD rules for Jag servers,

    Should I need this, since I have CSF installed and running?
    NO - you cannot run both!

  2. #17
    all about nothing! Frank Broughton's Avatar
    Join Date
    Jan 2006
    Posts
    2,158
    Be careful you do not block yourself. If you enter the wrong password so many times, it will block YOUR IP.... I have had that happen many times to users on my servers.

  3. #18
    Voluntarily Retired gohighvoltage's Avatar
    Join Date
    Jan 2011
    Posts
    641
    Thanks Frank, Appreciate the advice and help. So far this firewall is awesome. Anyone with a server should definitely install it.

  4. #19
    Voluntarily Retired gohighvoltage's Avatar
    Join Date
    Jan 2011
    Posts
    641
    I noticed since the install of CSF, that the numiptent use went a lot higher, not on the hard limit, but close. Is this a problem, or is there any way to limit the Number of IP packet filtering entries without reducing the protection of the firewall?

  5. #20
    Voluntarily Retired gohighvoltage's Avatar
    Join Date
    Jan 2011
    Posts
    641
    Installing CSF+LFD was the best thing I ever did!!! I am up to 150 IP addresses permanently blocked now for port scanning and attempts to brute force log in!!! Crazy!!!

  6. #21
    JPC Member
    Join Date
    Nov 2011
    Posts
    5

    Web Hosting?

    Is CSF+LFD for VPS hosting?

    I am using Jaguar’s Web Hosting Plan.

  7. #22
    JPC Dream Team JPC-Bilal's Avatar
    Join Date
    Nov 2006
    Posts
    1,175
    Hi Deyson,

    CSF-LFD is installed on all of our shared, sdx and reseller servers too. Thank you.

  8. #23
    JPC Member
    Join Date
    Nov 2011
    Location
    Australia
    Posts
    21
    Quote Originally Posted by gohighvoltage View Post
    I noticed since the install of CSF, that the numiptent use went a lot higher, not on the hard limit, but close. Is this a problem, or is there any way to limit the Number of IP packet filtering entries without reducing the protection of the firewall?
    That means CSF+LFD is doing its job, really. Sure you're aware of it now though since this is an older post.

    Quote Originally Posted by gohighvoltage View Post
    Installing CSF+LFD was the best thing I ever did!!! I am up to 150 IP addresses permanently blocked now for port scanning and attempts to brute force log in!!! Crazy!!!
    Haha, it's a pretty awesome script.

  9. #24
    Loyal Client
    Join Date
    Mar 2009
    Location
    Cincinnati, OH
    Posts
    63
    A very cool feature of csf is blocking whole countries. There is a limit in regards to how many rules iptables can handle before slowing down, so when I had China, Russia and Moldova blocked, it slowed the whole system down quite a bit (and prior to that the Jag admins had to chane a parameter on the VM outside of the operating system).
    The entry to block complete countries in /etc/csf/csf.conf is CC_DENY - The line CC_DENY = "CN,RU,MD" would block China, Russia, Moldovia :-)

  10. #25
    Voluntarily Retired gohighvoltage's Avatar
    Join Date
    Jan 2011
    Posts
    641
    Quote Originally Posted by Big Tom View Post
    A very cool feature of csf is blocking whole countries. There is a limit in regards to how many rules iptables can handle before slowing down, so when I had China, Russia and Moldova blocked, it slowed the whole system down quite a bit (and prior to that the Jag admins had to chane a parameter on the VM outside of the operating system).
    The entry to block complete countries in /etc/csf/csf.conf is CC_DENY - The line CC_DENY = "CN,RU,MD" would block China, Russia, Moldovia :-)
    Yeah, blocking Russia, China, and some other countries isn't a bad idea. Most of my attacks are from a few countries.

Page 2 of 2 FirstFirst 12

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •