Looking for recommendations for configuring csf.blocklists

roarkh

Verified User
Joined
Aug 30, 2005
Messages
139
Location
Bellingham, WA
Hi everyone,

I have csf v6.47 installed and noticed the "lfd Blocklists" button near the bottom of the interface, I had not noticed this before and at this time all of the entries in there are commented out. I am considering uncommenting some or all of the lists to see if it helps stop some spammers that are getting by the SpamBlocker lists I am subscribed to however there is the following warning which is putting me off from testing it since I don't have a "test" da server...
Code:
# Note: Some of thsese lists are very long (thousands of IP addresses) and
# could cause serious network and/or performance issues, so setting a value for
# the MAX field should be considered
I am interested in hearing how well this has worked for anyone that enabled this feature and have two primary questions.

1. Which lists did you choose to enable?

2. Did you leave the MAX setting at 0 or set it to something else (and if so, what)?

I appreciate any recommendations anyone can give.
 
I would never use something like that on a software firewall. Each time a connection is made it has to look through all those lists to see if its allowed or not. If your firewall list becomes too large you will see reduced connection speeds.
 
Back
Top