Firewall advices
I found those in the library:
. Control Network Traffic with iptables
. Using Fail2ban to Block Network Probes
Should i install both?
Anymore tips will be welcome.
Thank you.
11 Replies
You should use iptables and it's not a bad idea to use fail2ban.
It's pretty much the de facto standard for cpanel servers, however it does have gui's for direct admin and webmin as well as a cli option.
If so, do i access it through a browser?
It is always the first thing I set up on any new hardware.
I installed CSF, but in installation instructions it says to edit /etc/init.d/syslog and to make sure that any klogd lines are not commented out. But there is no syslog file in there. Do i have to install it?
Thanks
Check that - broken again.
I give up. Here is the suggested fix, but when I do this I am unable to log into my linode.
–--
I found this:
and this:
When I do this "fix" I'm unable to log into my linode unless I stop rsyslog.
LFD and the firewall still work. but without kernel logging I guess portscanning detection won't happen, and I think there are other problems with kernel logging not working in general but this is way beyond me.
Ran an online port scan and everything is working fine (messages showed up in /var/log/messages and CSF blocked it), so if you happen to be using Ubuntu 10.04 or higher with the kernel above, you shouldn't need to make any edits re: klogd.