Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 10 of 10
  1. #1
    Member
    Join Date
    Apr 2004
    Posts
    320

    Default Question about server load and PORTFLOOD setting in CSF/LFD

    Hi,

    Can someone please clearify if the following setting in CSF/LFD :

    Code:
    PORTFLOOD = "80;tcp;20;5"
    instead of the default one :

    Code:
    PORTFLOOD = ""
    will cause a noticable increase in server load? And further more if this increase in server load (if any) is neglectable when the increase in safety is taken into account?

    Thanks.

  2. #2
    Member
    Join Date
    Aug 2009
    Posts
    5

    Default

    I've noticed no load and I've gone as low as

    Code:
    PORTFLOOD = "80;tcp;10;5"

  3. #3
    Member
    Join Date
    Apr 2004
    Posts
    320

    Default

    Hi,

    Thanks for being the first to answer.

    That means you'll only allow ten connections per IP-address per five seconds. I'm not sure what type of server you're using but ain't that a bit low?

    I myself was thinking about :

    Code:
    PORTFLOOD = "80;tcp;20;1"
    (20 connections per IP-address per second to the httpd server)

  4. #4
    Member
    Join Date
    Aug 2009
    Posts
    5

    Default

    right now im running 25:5 to combat a 50k request per-second GET flood. it blocked most of it, but left another 10% of the attack for me to mitigate manually for a few hours.

  5. #5
    Member
    Join Date
    Apr 2004
    Posts
    320

    Default

    Hi Nikey,

    According to the documentation CSF does only count 20 hits at max :

    http://www.configserver.com/free/csf/readme.txt
    ...
    2. By default it only counts 20 packets per address remembered

    *This means that you need to keep the hit count to below 20.
    ...
    So I guess evey value above 20 won't work...

  6. #6
    Member
    Join Date
    Aug 2009
    Posts
    5

    Default

    i must have missed that... right now im running 20:3 which seems to do a pretty good job. imo, 20:1 just seems way too lose and would allow GET based floods through the firewall. I found 20:5 a good tight setting for heavy attacks.

  7. #7
    Member
    Join Date
    Apr 2004
    Posts
    320

    Default

    Hi Nikey,

    May I ask you what kind of services you're using the server CSF/LFD is installed on for?

    Thanks.

  8. #8
    Member
    Join Date
    Aug 2009
    Posts
    5

    Default

    Webhosting. So far I've not noticed any issues with the 20:3 settings. However, I'm thinking 20:5 might work alright as well. right now i've been toying with the settings a lot since im under a 75k per-second get flood.

  9. #9
    Member
    Join Date
    May 2010
    Posts
    321

    Default Re: Question about server load and PORTFLOOD setting in CSF/LFD

    Old thread this from a google find, Is the limit on CSF still in place or has this been changed.

    I mean

    PORTFLOOD = 80;tcp;40;1
    Or does the values have to be lower than 20 ? Such as:

    80;tcp;20;1
    as I was using:

    80;tcp;40;1
    Till I seen your port about limits....

  10. #10
    Member
    Join Date
    Apr 2004
    Posts
    320

    Default Re: Question about server load and PORTFLOOD setting in CSF/LFD

    Indeed a very old thread. Maybe it's better to ask the author of CSF/LFD yourself on its corresponding forum instead?

Similar Threads & Tags
Similar threads

  1. Help - lfd on server: High 5 minute load average alert - 6.15
    By efuzone in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 06-20-2011, 10:50 AM
  2. Question about server load and PORTFLOOD setting in CSF/LFD
    By Bdzzld in forum cPanel and WHM Discussions
    Replies: 9
    Last Post: 12-02-2010, 02:09 AM
  3. lfd alert for high server load. Who's the culprit?
    By schwim in forum cPanel and WHM Discussions
    Replies: 4
    Last Post: 09-03-2007, 08:53 PM
  4. CSF/LFD -- lfd.log question
    By bmcpanel in forum cPanel and WHM Discussions
    Replies: 3
    Last Post: 08-26-2007, 11:40 PM
  5. csf / lfd
    By chmod root in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 11-17-2006, 09:37 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube