The documentation for this says the only supported services are cpanel, whm,webmail and webdav but I see lots of services listed when using the feature in WHM, including smtp, ssh, ftp, imap, pop3 etc etc. Are these all supported?
Is there a practical limit to how many IP's / ranges can be used?
Does this feature use it's own service / process in front of each service? How does it work exactly?
Why won't it accept CIDR ranges?
Basically I'm looking for a more practical way to perform country based access control to certain services, without having lots of iptables rules.
I'd really like to use Maxmind's Geoip database to allow access to a specific service, (e.g, smtp) to a dozen or so countries, while denying everyone else. It would be awesome if someone developed a WHM plugin to do that.
In the meantime it occurred to me that I could simply convert the geoip country data into the format required and include the ranges in the hosts.allow file. I realise that this would consist of a couple of thousand entries and I don't know what effect that might have - but, as long as it only delayed the initial access to the service for a few seconds, it would probably be ok.
I think it would be of great benefit to have the ability to easily allow / deny access to specific services based on country and I'd be interested to hear your thoughts.
Is there a practical limit to how many IP's / ranges can be used?
Does this feature use it's own service / process in front of each service? How does it work exactly?
Why won't it accept CIDR ranges?
Basically I'm looking for a more practical way to perform country based access control to certain services, without having lots of iptables rules.
I'd really like to use Maxmind's Geoip database to allow access to a specific service, (e.g, smtp) to a dozen or so countries, while denying everyone else. It would be awesome if someone developed a WHM plugin to do that.
In the meantime it occurred to me that I could simply convert the geoip country data into the format required and include the ranges in the hosts.allow file. I realise that this would consist of a couple of thousand entries and I don't know what effect that might have - but, as long as it only delayed the initial access to the service for a few seconds, it would probably be ok.
I think it would be of great benefit to have the ability to easily allow / deny access to specific services based on country and I'd be interested to hear your thoughts.