Community Forums
Connect with us on LinkedIn
+ Reply to Thread
Results 1 to 2 of 2
  1. #1
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default csf / idf blocking IP but not putting it in deny file?

    Today, twice we found that someone's IP had been blocked in the firewall, but we could not find their IP in the /etc/csf/csf.deny file.

    Tried rebooting csf with

    service csf restart

    And even tried restarting iptables, then csf again, but this did not clear the issue.

    The issue was not cleared until I inserted the blocked IP in the csf allow file, and then restarted the firewall.

    Does anyone know what would cause this?

    And by the way, what is the grep command for iptables for checking just one IP to see if it has been banned?

    Thanks much for any response.

  2. #2
    Member
    Join Date
    Mar 2004
    Posts
    859

    Default

    Stranger and stranger:

    We have an IP that is being blocked by the kernal but is not in the iptables firewall:

    Server message log:

    Nov 27 21:42:47 stratus kernel: Firewall: *UDP_OUT Blocked* IN= OUT=eth0 SRC=[server ip here] DST=208.244.116.59 LEN=38 TOS=0x00 PREC=0x00 TTL=1 ID=6263 PROTO=UDP SPT=48042 DPT=33435 LEN=18


    But:

    iptables -L -n | grep 208.244.116.59

    .. returns nothing.

    How could this have occurred?

Similar Threads & Tags
Similar threads

  1. Replies: 5
    Last Post: 02-14-2011, 04:12 AM
  2. CSf Firewall: Edit csf.deny, the IP address deny file (Currently:1000 permanent IP b
    By crazyaboutlinux in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 12-09-2010, 06:23 AM
  3. Csf Blocking???
    By logikstudios in forum cPanel Developers
    Replies: 1
    Last Post: 04-28-2007, 04:25 AM
  4. CSF firewall - "Manually denied" in the csf.deny file?
    By jols in forum cPanel and WHM Discussions
    Replies: 1
    Last Post: 04-05-2007, 07:10 AM
  5. Blocking a range of IP's in the IP deny manager
    By AbeFroman in forum cPanel and WHM Discussions
    Replies: 10
    Last Post: 02-19-2005, 01:23 PM
Linkedin       Facebook       Twitter       RSS       Flickr       YouTube