Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 5 of 5
  1. #1
    Member sh4ka's Avatar
    Join Date
    May 2005
    Posts
    434

    Default APF antidos logs ?

    I've installed and activated the anti-dos functions for APF, but after a few days I check for the logs, and I can't even find the log file at /var/log/apfados_log.

    What does this mean, that no one launched DOS attacks against my box, or that simply the mod antidos is not working ? How can I know if it is working ?

    I'm using RHAS.

    thzk!

  2. #2
    Member
    Join Date
    Apr 2003
    Location
    Lewisville, Tx
    Posts
    968

    Default

    It shouldn't really log anything in the AD logs unless it does something. Look in your master APF logs and it should tell you that AD started up properly or not. Check that the AD/APF crons are running properly, they are located in /etc/cron.
    Kris
    NCServ, LLC.
    WebHosting - Dedicated Servers - Colocation
    sales@ncerv.com

  3. #3
    Member
    Join Date
    May 2005
    Posts
    36

    Default

    You could see if it is working or not by trying to DoS it yourself?

    Bear in mind that you need to get access some other way to disable the block it will put on your IP.

  4. #4
    Member avijit's Avatar
    Join Date
    Jul 2004
    Location
    India
    Posts
    116

    Default

    By default the file /var/log/apfados_log is not created so that it can keep the log. And you need to have a DOS to get logs there to have some logs as mentioned earlier.

    You can touch that file to create it and see what heppens
    Stop Reymond !! A single conversation with a wise man is better than ten years of study. So....

  5. #5
    Member avijit's Avatar
    Join Date
    Jul 2004
    Location
    India
    Posts
    116

    Default

    Another thing..if this helps ...
    AD is not going to pickup and block a lot of things normally (unless you put the settings to low, but then you'll be blocking innocent people). It's meant to block IP's that are doing a DDoS attack, so unless your getting an syn flood attack or something like this, you really should not see any IP's being added.
    Anti DOS rules can be kept at /etc/apf/ad/ad.rules

    You need to set USE_AD="1" in the /etc/apf/conf.apf to get those rules working.

    You may see some logs there if you reduce the LRATE="45" But I am sure you will not.
    Stop Reymond !! A single conversation with a wise man is better than ten years of study. So....

Similar Threads & Tags
Similar threads

  1. APF firewall help - antidos
    By hostseeker in forum cPanel and WHM Discussions
    Replies: 5
    Last Post: 03-08-2006, 03:23 PM
  2. APF antidos
    By DigitalKeg in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 03-03-2006, 12:01 PM
  3. Brute Force Warning : Executed actions: /etc/apf/apf -d at
    By isputra in forum cPanel and WHM Discussions
    Replies: 6
    Last Post: 02-22-2006, 06:44 PM
  4. how do i stop apf antidos
    By radical in forum cPanel Developers
    Replies: 7
    Last Post: 07-13-2005, 08:48 PM
  5. apf firewall/antidos upcp problem
    By Kasper.S in forum cPanel and WHM Discussions
    Replies: 2
    Last Post: 09-04-2004, 09:51 AM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube