Richard G
Verified User
As for the exim issues, check for csf.deny or tempdeny if they are indeed blocked.
				
			# User Attacks
if (($lgfile eq $config{CUSTOM2_LOG}) and ($line =~ /^(.+) login authenticator failed for \(User\) \[(\S+)\]: 535 Incorrect authentication data/))  {
      return ("User Attack From ",$2,"UserAttack","5","25,110,995,587,465","1");
   }That depends on your system. However if it's set to 0, as described many things will not work.PS: Should RESTRICT_SYSLOG in /etc/csf/csf.conf be valued "0" ? That's its current value.