No idea what exactly is banning an IP on the CentOS server

acdomains

Verified User
Joined
May 2, 2007
Messages
14
Hi guys,

I have a CentOS server (with DA installed, of course :) ) running APF as the firewall. A few weeks ago I've installed BFD + ddos + mod_security + mod_evasive. The problem is that couple days ago I noticed that my home IP is banned in APF. I SSHd from another IP and found that my IP is erased from /etc/apf/allow_hosts.rules and added to /etc/apf/deny_hosts.rules with _empty_ comment. I doubllechecked the setting of the DDoS-Deflate script and confirmed that my ip is listed in the ignore.ip.list file.

What else can erase my IP from the white list and add it to the black one?

thanks
 
nope, I am the only person that has root access to the server. This is the only strange activity that I noticed within the server.
 
Nope :( updating the APF haven't brought me to the desired result.
The only possible/suitable solution found if an shell script being ran on a cron schedule that verifies the APF's deny_hosts.rules and unbans the required IPs.
 
Back
Top