patrickkasie
Verified User
Dear DirectAdmin forums,
I'm not entirely sure how CSF works. Is it supposed to still let incoming connections through and then block requests? I am not sure how to best ask my question, which is probably what I need help with the most. Anyway, I've written down an entire range of IP addresses to block access to our server, but it's still adding new IP addresses to the list within said range. Did I make a syntactically correct record or did I make a user error? Why are there still new records coming in and mails being sent to my inbox that these brute-force attacks are still happening?
The following records are in my /etc/csf/csf.deny file
# CIDR addressing allowed with a quaded IP (e.g. 192.168.254.0/24)
46.148.40.0/24 # do not delete
46.148.40.186 # BFM: exim2=123 (IR/Iran/-) - Wed Sep 27 22:08:56 2023
46.148.40.185 # BFM: exim2=123 (IR/Iran/-) - Wed Sep 27 22:10:56 2023
I'm not entirely sure how CSF works. Is it supposed to still let incoming connections through and then block requests? I am not sure how to best ask my question, which is probably what I need help with the most. Anyway, I've written down an entire range of IP addresses to block access to our server, but it's still adding new IP addresses to the list within said range. Did I make a syntactically correct record or did I make a user error? Why are there still new records coming in and mails being sent to my inbox that these brute-force attacks are still happening?
The following records are in my /etc/csf/csf.deny file
# CIDR addressing allowed with a quaded IP (e.g. 192.168.254.0/24)
46.148.40.0/24 # do not delete
46.148.40.186 # BFM: exim2=123 (IR/Iran/-) - Wed Sep 27 22:08:56 2023
46.148.40.185 # BFM: exim2=123 (IR/Iran/-) - Wed Sep 27 22:10:56 2023