I am loosing my mind over here. I have an abusive IP that I need to block. I use CSF and added the IP to the deny list. I can search for the IP and see that it's added in the firewall, but it still posts requests to my website. I dropped all IP's from the deny list except this one for testing, but no luck. I also switched from my default using IPSET to non-IPSET and the firewall rules clearly show the IP in the denyin chain, but it still gets through!!! How on earth?!! I checked the allow list to see if the IP was also listed there but it wasn't.
I have been using CSF for years and I have never seen this. I double checked for typos multiple times. I just copy the IP from my access logs so typos are practically impossible. So what is going on here? I could use any bump in the right direction. I am probably doing something very wrong but I can't seem to figure out what it is.
I have been using CSF for years and I have never seen this. I double checked for typos multiple times. I just copy the IP from my access logs so typos are practically impossible. So what is going on here? I could use any bump in the right direction. I am probably doing something very wrong but I can't seem to figure out what it is.