csf suddenly blocking all ipv4 access

2 posts Page 1 of 1
izghitu
Junior Member
Posts: 12
Joined: 15 Jan 2008, 09:08


Hi,

I have latest csf/lfd running on CloudLinux 6 with cPanel. The problem I started experiencing is that without any reason csf blocks all ipv4 access to the server. This repeated 2 times already. When it happens I can see the following in the lfd logs:
Code: Select all
May 23 23:53:36 wp03 lfd[1563049]: Global DynDNS - update IP addresses
May 23 23:53:36 wp03 lfd[1563049]: Global DynDNS: Lookup for [<!DOCTYPE] failed
May 23 23:53:36 wp03 lfd[1563049]: Global DynDNS: Lookup for [.07em] failed
May 23 23:53:36 wp03 lfd[1563049]: Global DynDNS: Lookup for [!important}</style><script] failed
May 24 00:00:03 wp03 lfd[141386]: Main Process: TERM
May 24 00:00:03 wp03 lfd[141386]: daemon stopped
May 24 00:00:03 wp03 lfd[1568898]: daemon started on  - csf v12.11 (cPanel)
May 24 00:00:03 wp03 lfd[1568898]: LF_APACHE_ERRPORT: Set to [2]
May 24 00:00:03 wp03 lfd[1568898]: EasyApache4, using /etc/apache2/logs/error_log instead of /usr/local/apache/logs/error_log (Web Server)
May 24 00:00:03 wp03 lfd[1568898]: EasyApache4, using /etc/apache2/logs/error_log instead of /usr/local/apache/logs/error_log {ModSecurity}
May 24 00:00:03 wp03 lfd[1568898]: CSF Tracking...
May 24 00:00:03 wp03 lfd[1568898]: csf is currently restarting - command [/sbin/iptables  -L LOCALINPUT -n] skipped on line 3096
May 24 00:00:03 wp03 lfd[1568898]: iptables appears to have been flushed - running *csf startup*...
May 24 00:00:03 wp03 lfd[1568898]: csf is currently restarting - command [/usr/sbin/csf -sf] skipped on line 3105
May 24 00:00:04 wp03 lfd[1568898]: *Error*: csf output: Error: csf is being restarted, try again in a moment: Resource temporarily unavailable at /usr/sbin/csf line 175.

May 24 00:00:04 wp03 lfd[1568898]: csf startup completed
May 24 00:00:04 wp03 lfd[1568898]: IPv6 Enabled...
May 24 00:00:04 wp03 lfd[1568898]: DynDNS Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Global Ignore Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Global Allow Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Global Deny Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Global DynDNS Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Country Code Lookups...
May 24 00:00:04 wp03 lfd[1569049]: csf is currently restarting - section [DYNDNS] skipped
May 24 00:00:04 wp03 lfd[1568898]: System Integrity Tracking...
May 24 00:00:04 wp03 lfd[1569054]: csf is currently restarting - command [/usr/bin/md5sum --check /var/lib/csf/csf.tempint] skipped on line 6944
May 24 00:00:04 wp03 lfd[1568898]: Exploit Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Directory Watching...
May 24 00:00:04 wp03 lfd[1568898]: Directory File Watching...
May 24 00:00:04 wp03 lfd[1568898]: Email Script Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Email Queue Tracking...
May 24 00:00:04 wp03 lfd[1568898]: ModSecurity IP D/B Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Temp to Perm Block Tracking...
May 24 00:00:04 wp03 lfd[1568898]: System Statistics...
May 24 00:00:04 wp03 lfd[1569057]: csf is currently restarting - command [/usr/sbin/exim -bpc] skipped on line 3416
May 24 00:00:04 wp03 lfd[1568898]: WHM Tracking...
May 24 00:00:04 wp03 lfd[1568898]: Watching /usr/local/cpanel/logs/access_log...
May 24 00:00:04 wp03 lfd[1568898]: Watching /var/log/messages...
May 24 00:00:04 wp03 lfd[1568898]: Watching /var/log/secure...
May 24 00:00:04 wp03 lfd[1568898]: Watching /var/log/exim_mainlog...
May 24 00:00:04 wp03 lfd[1568898]: Watching /etc/apache2/logs/error_log...
May 24 00:00:04 wp03 lfd[1568898]: Watching /usr/local/cpanel/logs/login_log...
May 24 00:00:04 wp03 lfd[1568898]: Watching /var/log/maillog...
May 24 00:00:09 wp03 lfd[1568898]: *Error* You have an unresolved error when starting csf. You need to restart csf successfully before restarting lfd (see /etc/csf/csf.error). *lfd stopped*, at line 1118
May 24 00:00:09 wp03 lfd[1568898]: daemon stopped
Any ideas?
The only to fix this is to run csf -r but the above happens again after a day or 2.

Please help
Thanks
aresko
Junior Member
Posts: 2
Joined: 13 Jun 2019, 16:12


There shouldn't be any issues with using CSF and cPHulk at the same time. You can disable firewall level blocking as you noted you might do to ensure that you don't double block something but it's doubtful you'd even run into an issue in this instance. You might watch it for a while and compare IP's on cPhulk's hitlist to IP's blocked with CSF.
Sarkari Result Pnr Status 192.168.1.1
2 posts Page 1 of 1