Sponsor:

Server and Web Integrator
Link:
Kloxo-MR logo
6.5.0 or 7.0.0
Click for "How to install"
Donation/Sponsorship:
Kloxo-MR is open-source.
Donate and or Sponsorship always welcome.
Click to:
Click Here
Please login or register. 2024-04-27, 08:03:30

Author Topic: [csf] ConfigServer Security & Firewall  (Read 4307 times)

0 Members and 1 Guest are viewing this topic.

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
[csf] ConfigServer Security & Firewall
« on: 2013-12-27, 14:10:22 »
Hello Mustafa,

Sad to know what happened with the forum and crash...

I found that following would be so fantastic to have it integrated in Kloxo-MR as a builtin package:

http://configserver.com/cp/csf.html

In particular, I found the "Port Flood Protection" as one of the MOST IMPORTANT TOOL to block connections EVEN BEFORE THE SPAMDYKE plays its role.

I have configured as follows:

PORTFLOOD = 22;tcp;1;60,25;tcp;3;60,80;tcp;10;60

---> 25;tcp;3;60

which means that the csf (firewall) shall allow within 60 sec. ONLY THREE CONNECTIONS from a particular IP on Port 25.

Spamdyke will not even be activated for processing as csf blocks the connection activity so beautifully.

Since many days, I see port flooding on 25 port. Hence, this solution is a must.

Kloxo-MR comes must later. In the sequence, CSF ---> spamdyke ---> Qmail/Kloxo-MR.
« Last Edit: 2013-12-28, 01:29:52 by Kloxo-DR »

Offline MRatWork

  • Administrator
  • The Elite
  • *****
  • Posts: 15,807
  • Karma: +119/-11
  • Gender: Male
    • View Profile
    • MRatWork Forum
Re: [csf] ConfigServer Security & Firewall
« Reply #1 on: 2013-12-27, 15:15:04 »
I am still thinking using other firewall (csf or iptables) is useless.

Enough using lxguard and nginx/hiawatha (proxy or standalone).
..:: MRatWork (Mustafa Ramadhan Projects) ::..
-- Server/Web-integrator - Web Hosting (Kloxo-MR READY!) --

Offline chrisf

  • Senior Master
  • **
  • Posts: 883
  • Karma: +11/-1
  • Gender: Male
  • Be the change that you wish to see in the world.
    • View Profile
    • Conviction's Hosting
Re: [csf] ConfigServer Security & Firewall
« Reply #2 on: 2013-12-27, 18:14:05 »
Your settings for HTTP (port 80) are too restrictive.  If you or your clients are running a CMS ten connections is not enough in a 60 second block.  Reason is every connection from the browser counts.  This includes asynchronous loading of JavaScript, images, CSS files, etc.  I would set that no lower than 75.  If it is an attack, 75 will easily catch your attack.  For social sites (clients) I keep the number on those servers are 125.

A simple Ajax based chat script will hit 10 and then block your clients customers falsely.
Christopher

Knowledge in: PHP, Perl, MySQL, Javascript, Actionscript, FLASH, HTML, CSS
Server Administrator / Developer: https://convictionshosting.com

Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [csf] ConfigServer Security & Firewall
« Reply #3 on: 2013-12-28, 01:35:08 »
Hello Chris,

In fact I was just playing on my test server and now need to copy csf to production /etc.

What a valuable piece of advise!

Thanks.




Offline Kloxo-DR

  • Senior Member
  • *
  • Posts: 239
  • Karma: +3/-9
    • View Profile
Re: [csf] ConfigServer Security & Firewall
« Reply #4 on: 2013-12-28, 01:41:24 »
Hi Mustafa,

I am still thinking using other firewall (csf or iptables) is useless.
Enough using lxguard and nginx/hiawatha (proxy or standalone).

Of course both have some protection in built in them.

However csf has features that are not inbuilt in lxguard or nginx/hiawatha.

It is just very wrong to be too proud of a software, where use of other software with advanced features are not only just helpful but INEVITABLE!

I just think csf is inevitable. There is no chance that lxguard or nginx/hiawatha could be any closer to functionality offered by csf firewall.

However, it is your decision tto not to integrate it tighetly in kloxo-mr.

It is integrated in zPanel, though.

 


Top 10 Social Networking:    Facebook    Twitter    LinkedIn    Pinterest    Google Plus    Tumblr    Instagram    VK    Flickr    Vine
Click Here

Page created in 0.039 seconds with 19 queries.

web stats analysis