Hi Richard,
Thank you for your help and patience with me; highly appreciated.
Okay, so I redid everything and now I am using the following:
sudo systemctl stop nftables
sudo systemctl disable nftables
sudo systemctl mask --now nftables
sudo systemctl stop firewalld
sudo systemctl disable firewalld
sudo systemctl mask --now firewalld
sudo dnf remove -y nftables
sudo dnf install -y iptables-services
sudo systemctl stop iptables
sudo systemctl stop ip6tables
sudo systemctl disable iptables
sudo systemctl disable ip6tables
Unless I overlooked things (again), this should be correct, right?
When I run service iptables/ip6tables status I get the following:
Redirecting to /bin/systemctl status iptables.service
● iptables.service - IPv4 firewall with iptables
Loaded: loaded (/usr/lib/systemd/system/iptables.service; disabled; vendor preset: disabled)
Active: inactive (dead)
Redirecting to /bin/systemctl status ip6tables.service
● ip6tables.service - IPv6 firewall with ip6tables
Loaded: loaded (/usr/lib/systemd/system/ip6tables.service; disabled; vendor preset: disabled)
Active: inactive (dead)
That should be correct.
I also tested what you said: iptables -L & ip6tables -L
Both show information now. Which is good.
Also CSF is up and running, however I did notice an error?
Redirecting to /bin/systemctl status csf.service
● csf.service - ConfigServer Firewall & Security - csf
Loaded: loaded (/usr/lib/systemd/system/csf.service; enabled; vendor preset: disabled)
Active: active (exited) since Fri 2020-11-27 12:49:14 CET; 3min 13s ago
Process: 472 ExecStart=/usr/sbin/csf --initup (code=exited, status=0/SUCCESS)
Main PID: 472 (code=exited, status=0/SUCCESS)
Tasks: 0 (limit: 3200)
Memory: 0B
CGroup: /system.slice/csf.service
Nov 27 12:49:14 dns01.example.com csf[472]: csf: FASTSTART loading SMTP Block (IPv4)
Nov 27 12:49:14 dns01.example.com csf[472]: csf: FASTSTART loading SMTP Block (IPv6)
Nov 27 12:49:14 dns01.example.com csf[472]: csf: FASTSTART loading DNS (IPv4)
Nov 27 12:49:14 dns01.example.com csf[472]: csf: FASTSTART loading DNS (IPv6)
Nov 27 12:49:14 dns01.example.com csf[472]: iptables v1.8.4 (nf_tables): RULE_INSERT failed (No such file or directory): rule in chain OUTPUT
Nov 27 12:49:14 dns01.example.com csf[472]: LOCALOUTPUT all opt -- in * out !lo 0.0.0.0/0 -> 0.0.0.0/0
Nov 27 12:49:14 dns01.example.com csf[472]: LOCALINPUT all opt -- in !lo out * 0.0.0.0/0 -> 0.0.0.0/0
Nov 27 12:49:14 dns01.example.com csf[472]: LOCALOUTPUT all opt in * out !lo ::/0 -> ::/0
Nov 27 12:49:14 dns01.example.com csf[472]: LOCALINPUT all opt in !lo out * ::/0 -> ::/0
Nov 27 12:49:14 dns01.example.com systemd[1]: Started ConfigServer Firewall & Security - csf.
No clue if that is important or not, but just wondering.
There does seem to be an issue with LFD though:
Redirecting to /bin/systemctl status lfd.service
● lfd.service - ConfigServer Firewall & Security - lfd
Loaded: loaded (/usr/lib/systemd/system/lfd.service; enabled; vendor preset: disabled)
Active: activating (start) since Fri 2020-11-27 12:55:01 CET; 29s ago
Cntrl PID: 2067 (lfd)
Tasks: 2 (limit: 3200)
Memory: 16.4M
CGroup: /system.slice/lfd.service
├─2067 /usr/bin/perl /usr/sbin/lfd
└─2074 /sbin/iptables --wait -L PREROUTING -t raw
Nov 27 12:55:01 dns01.example.com systemd[1]: Starting ConfigServer Firewall & Security - lfd...
Eventually it fails and tries to restart (over and over).
Because of this (?) logging in DirectAdmin lags. Also opening "ConfigServer Security & Firewall" takes ages and is quite unresponsive.
Also I am getting messages in the "Messsage Center" that "lfd' is down.
If I check the lfd.log it shows the following errors (not much else):
Nov 27 12:35:06 ns1 lfd[434394]: Retrieved and blocking blocklist DSHIELD IP address ranges
Nov 27 12:35:06 ns1 lfd[434394]: *Error* FASTSTART: (Blocklist [DSHIELD] IPv4) [] [iptables-restore: line 2 failed]
Nov 27 12:35:06 ns1 lfd[434394]: Retrieved and blocking blocklist MAXMIND IP address ranges
Nov 27 12:35:06 ns1 lfd[434394]: *Error* FASTSTART: (Blocklist [MAXMIND] IPv4) [] [iptables-restore: line 2 failed]
Nov 27 12:35:07 ns1 lfd[434394]: Retrieved and blocking blocklist BFB IP address ranges
Nov 27 12:35:07 ns1 lfd[434394]: *Error* FASTSTART: (Blocklist [BFB] IPv4) [] [iptables-restore: line 2 failed]
I will remove those entries from the blocklists. Maybe those don't work anymore for some reason.
In the meantime I will test it some more.
I have no clue what else can be wrong here though.
Regards