Search found 74 matches

by aww+
18 Sep 2015, 21:42
Forum: General Discussion (csf)
Topic: ipset v6.19: Sets cannot be swapped: the second set does not exist
Replies: 2
Views: 3451

ipset v6.19: Sets cannot be swapped: the second set does not exist

showed up today in the logs Retrieved and blocking blocklist XYZ IP address ranges IPSET: loading set new_XYZ with 167 entries IPSET: switching set new_XYZ to bl_XYZ *Error* IPSET: [ipset v6.19: Sets cannot be swapped: the second set does not exist] (btw on another server not using IPSET the blockli...
by aww+
11 Sep 2015, 21:07
Forum: General Discussion (csf)
Topic: where are the built-in rbl lists?
Replies: 3
Views: 3132

Re: where are the built-in rbl lists?

Does the rblcheck code use the local dns resolver to query the rbl?

Or does it bypass dns and make its own direct call to the rbl server?
by aww+
11 Sep 2015, 21:06
Forum: General Discussion (csf)
Topic: where are the built-in rbl lists?
Replies: 3
Views: 3132

Re: where are the built-in rbl lists?

aha, finally found it /usr/local/csf/lib/ConfigServer/RBLCheck.pm imports /usr/local/csf/lib/csf.rbls which currently contains 43 servers I kind of wish it was just externalized into /etc/csf/ Because since csf.rbls can change with every upgrade, it can just include more and more rbls Unless there i...
by aww+
11 Sep 2015, 20:58
Forum: General Discussion (csf)
Topic: where are the built-in rbl lists?
Replies: 3
Views: 3132

where are the built-in rbl lists?

Grepping is not helping me here, maybe I am searching badly.

I assume the hard coded internal list was chosen for a reason instead of the blocklist method where they are externalized by default?
by aww+
11 Sep 2015, 20:56
Forum: General Discussion (csf)
Topic: csf.blocklists being replaced
Replies: 1
Views: 2237

Re: csf.blocklists being replaced

I've never seen my blocklist change but if you cannot figure out where it is coming from

chattr +i /etc/csf.blocklists

will stop anything from writing to it or deleting it (including you)

just remember to do a -i before you edit it
by aww+
11 Sep 2015, 20:43
Forum: Suggestions (csf)
Topic: feature request: UI_IP = 12.34.56.78
Replies: 2
Views: 3608

Re: feature request: UI_IP = 12.34.56.78

You guys (and gals?) are fantastic. Keep up the great work.
by aww+
03 Sep 2015, 19:27
Forum: Report Bugs (csf)
Topic: ServerCheck.pm reports DNS recursion but bind/named not installed
Replies: 1
Views: 6314

ServerCheck.pm reports DNS recursion but bind/named not installed

None of these files exist my @files = ("/var/named/chroot/etc/named.conf","/etc/named.conf","/etc/bind/named.conf","/var/named/chroot/etc/bind/named.conf"); we use dnsmasq but still get "Check for DNS recursion restrictions" (dnsmasq is set to only l...
by aww+
29 Aug 2015, 11:31
Forum: General Discussion (csf)
Topic: FASTSTART iptables-restore errors on openvz but numiptent is unlimited?
Replies: 1
Views: 1834

Re: FASTSTART iptables-restore errors on openvz but numiptent is unlimited?

I seem to have temporarily resolved this by decreasing CC_DROP_CIDR to 17 from 18 It decreased numiptent to 16K (16 makes it 15K but allows too many networks in) Maybe the container is being lied to that it is unlimited, but there is still no barrier failure count. It would be interesting if someday...
by aww+
29 Aug 2015, 11:20
Forum: Suggestions (csf)
Topic: csf -ra should confirm it is restarting LFD
Replies: 1
Views: 2776

csf -ra should confirm it is restarting LFD

Thanks for the new csf -ra feature

However it would be nice at the end if it would confirm it is restarting LFD, and maybe even pause to watch and wait to see LFD successfully restarts and mention that too?
by aww+
28 Aug 2015, 20:44
Forum: General Discussion (csf)
Topic: FASTSTART iptables-restore errors on openvz but numiptent is unlimited?
Replies: 1
Views: 1834

FASTSTART iptables-restore errors on openvz but numiptent is unlimited?

I've read previously here where numiptent limits have been blamed for FASTSTART failures when blocklists are downloaded/added *Error* FASTSTART: (Blocklist IPv4) [iptables-restore: line 2 failed] except my openvz contain has no limit on numiptent - what else can I check ? numiptent 18036 18036 92233...