Dublin-based cpanel ip addresses in

jeffschips

Well-Known Member
Jun 5, 2016
337
52
78
new york
cPanel Access Level
Root Administrator
Is it normal to see the following entries in:

In cpanel.allow
52.213.169.7 dublin
34.254.37.129 dublin
52.51.23.204 dublin

In cpanel.allow
192.36.148.17 dns
193.0.14.129 dns

??
 
Last edited by a moderator:

cPRex

Jurassic Moderator
Staff member
Oct 19, 2014
16,517
2,607
363
cPanel Access Level
Root Administrator
Thanks for the clarification - the cpanel.allow file is prepopulated by CSF, and my personal server does have those entries.

csf.allow is manually configured so someone had to add those entries for the DNS at some point.
 

jeffschips

Well-Known Member
Jun 5, 2016
337
52
78
new york
cPanel Access Level
Root Administrator
I just discovered that the csf.allow entries are for root servers dns service in Europe and an internet time server in Sweden.
Don't know why there and not the U.S. for both of them???
 

mtindor

Well-Known Member
Sep 14, 2004
1,516
142
343
inside a catfish
cPanel Access Level
Root Administrator
Interesting.

tcp|in|d=80|s=52.51.23.204 # cPanel SaaS Server
tcp|in|d=443|s=52.51.23.204 # cPanel SaaS Server
tcp|in|d=8443|s=52.51.23.204 # cPanel SaaS Server

tcp|in|d=80|s=52.213.169.7 # cPanel SaaS Server
tcp|in|d=443|s=52.213.169.7 # cPanel SaaS Server
tcp|in|d=8443|s=52.213.169.7 # cPanel SaaS Server

tcp|in|d=80|s=34.254.37.129 # cPanel SaaS Server
tcp|in|d=443|s=34.254.37.129 # cPanel SaaS Server
tcp|in|d=8443|s=34.254.37.129 # cPanel SaaS Server

What the hell is this all about? And TCP 8443? I've never had anything running on TCP 8443.

I don't like any of those Amazon IPs being allowed anywhere. Are these really used by cPanel for communications with cPanel servers?
 

mtindor

Well-Known Member
Sep 14, 2004
1,516
142
343
inside a catfish
cPanel Access Level
Root Administrator
Once again, we don't make or distribute CSF.
Understood. But maybe you could find out if the aforementioned servers are really cPanel operated (on Amazon) and if so, do they truly need inbound connection access to every server? I don't see anything in any cPanel documentation mentioning them. I plan on asking Chirpy, but cPanel would know better than him whether those IPs are legitimate IPs operating cPanel services that need to make inbound connections to our servers.