LFD and port scanning false positive

upsforum

Well-Known Member
Jul 27, 2005
474
0
166
I activated SSH access of my customer with a virtual host, the problem is that LFD blocked its ip with port scanning motivation:

Dec 11 15:51:10 vps4 lfd[18580]: *Port Scan* detected from 00.000.00.000 (IT/Italy/host000-000-static.000-00-b.business.telecomi...). 11 hits in the last 171 seconds - *Blocked in csf* for 3600 secs [PS_LIMIT]

- - - Updated - - -

I have this values in configuration file

PS_INTERVAL = Default: 300 [0 or 60-3600]
PS_LIMIT = Default: 10 [2-20]
PS_PORTS = 0:65535,ICMP
PS_DIVERSITY = Default: 1 [1-100]
PS_PERMANENT = Default: 0 [0-1]
PS_BLOCK_TIME = Default: 3600 [300-86400]
PS_EMAIL_ALERT = Default: 1 [0-1]
 

cPanelMichael

Administrator
Staff member
Apr 11, 2011
47,880
2,261
463
Hello :)

Keep in mind that any issues directly related to LFD/CSF are better handled directly on their support forums.

Thank you.