SOLVED Configserver deny listing IPs blacklisted by cPHulk Country blocks?

willke

Well-Known Member
Mar 30, 2005
67
4
158
Hi,

Noticed an unanswered thread over on Configserver forum which also applies to me. My Configserver "deny list" includes IPs which should have been blocked by cPHulk Country blacklists - is there an order of precedence in operation here where cPHulk Country blacklists only kick-in AFTER Configserver rules?

Will
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,909
2,228
463
Hello Will,

The Countries Management feature with cPHulk Brute Force Protection lists countries that you can whitelist, blacklist, or remove from either list. The whitelist specifies the IP addresses that cPHulk always allows to log in to your server. The blacklist specifies the IP addresses that cPHulk never allows to log in to your server. It's not actually blocking these IP addresses at the firewall. Instead, it's used to determine if the login attempt will succeed. Thus, CSF/LFD may still detect the login failures since the authentication attempt itself isn't blocked.

Thank you.
 

willke

Well-Known Member
Mar 30, 2005
67
4
158
Hello Will,

The Countries Management feature with cPHulk Brute Force Protection lists countries that you can whitelist, blacklist, or remove from either list. The whitelist specifies the IP addresses that cPHulk always allows to log in to your server. The blacklist specifies the IP addresses that cPHulk never allows to log in to your server. It's not actually blocking these IP addresses at the firewall. Instead, it's used to determine if the login attempt will succeed. Thus, CSF/LFD may still detect the login failures since the authentication attempt itself isn't blocked.

Thank you.
Thanks, Michael.
 
  • Like
Reactions: cPanelMichael

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,909
2,228
463
Attacks from Russia and China are still showing up despite adding them to the country block list. Is there a way to update the IP address ranges listed for these countries?
Hello Glen,

The cPHulk country blacklist specifies the IP addresses that cPHulk never allows to log in to your server. It's not actually blocking these IP addresses at the firewall level. You can use a firewall management utility such as CSF if you want to block countries from connecting to your server.

Thank you.