I set up DirectAdmin to add bfd ip's to the CSF ban (deny) list with help of these tutorials:
This works almost perfectly.
There are two issues:
1) CSF only keeps 200 records, when a new record is added, the oldest record is removed.
The problem is that some of these OLD IP's start a new attack. As DirectAdmin has these IP's still listed as "Blocked IPs" (brute force monitor), these IP's won't be added again to CSF.
It's possible to higher the number in CSF of 200, but this is not a solution as it will slow things down.
Would it be a solution to erase the "Blocked IPs" daily? If so, where is it located?
2) The Skip list works, but it still sends out an messages (e-mails) for the users/ip's. Can I disable this somehow?
Thank you!
This works almost perfectly.
There are two issues:
1) CSF only keeps 200 records, when a new record is added, the oldest record is removed.
The problem is that some of these OLD IP's start a new attack. As DirectAdmin has these IP's still listed as "Blocked IPs" (brute force monitor), these IP's won't be added again to CSF.
It's possible to higher the number in CSF of 200, but this is not a solution as it will slow things down.
Would it be a solution to erase the "Blocked IPs" daily? If so, where is it located?
2) The Skip list works, but it still sends out an messages (e-mails) for the users/ip's. Can I disable this somehow?
Thank you!
