CSF/LFD: Difference between revisions

From Leo's Notes
This page was last edited on 1 December 2019, at 22:00.
m Text replacement - "Category:Linux{{Navbox Linux}}" to "{{Navbox Linux}}Category:Linux"
mNo edit summary
Line 1: Line 1:


== Logging ==
== Logging ==
CSF/LFD automatically logs to /var/log/lfd.log
CSF/LFD automatically logs to {{code|/var/log/lfd.log}}.
tail /var/log/lfd.log
{{highlight|lang=terminal|code=
# tail /var/log/lfd.log
}}


== Quick Usage ==
{| class="wikitable"
! Task
! Command
|-
| Deny IP ||  {{highlight|lang=terminal|code=# csf -d <IP>}}
|- 
| Allow IP || {{highlight|lang=terminal|code=# csf -a <IP>}}
|-
| Remove Denial || {{highlight|lang=terminal|code=# csf -dr <IP>}}
|-
| Remove Allow || {{highlight|lang=terminal|code=# csf -ar <IP>}}
|-
| Temporary Denial || {{highlight|lang=terminal|code=# csf -td <IP> <seconds>}}
|}


== Block / Unblock IP ==


csf -d <IP> : block IP
== Automatic Temporary Bans ==
csf -a <IP> : allow IP
Ghetto script to quickly block clients making excessive connections:
csf -dr <IP> : Deny removal
{{highlight|lang=bash|code=
csf -ar <IP> : Allow removal
#!/bin/bash
 
# Any clients connecting to the server resulting in 20 or more
# connections will be blocked for 5 mins.
/usr/bin/netstat -n \
        {{!}} grep tcp {{!}} awk '{print $5}' \
        {{!}} awk -F: '{print $1}' {{!}} sort {{!}} uniq -c \
        {{!}} awk '$1 > 20 {print $2}' \
        {{!}} while read i ; do
                echo Temporarily blocking $i >> /tmp/csf.log
                /usr/sbin/csf -td $i 300
        done
}}




{{Navbox Linux}}[[Category:Linux]]
{{Navbox Linux}}[[Category:Linux]]

Revision as of 22:00, 1 December 2019

Logging

CSF/LFD automatically logs to /var/log/lfd.log.

# tail /var/log/lfd.log

Quick Usage

Task Command
Deny IP
# csf -d <IP>
Allow IP
# csf -a <IP>
Remove Denial
# csf -dr <IP>
Remove Allow
# csf -ar <IP>
Temporary Denial
# csf -td <IP> <seconds>


Automatic Temporary Bans

Ghetto script to quickly block clients making excessive connections:

#!/bin/bash

# Any clients connecting to the server resulting in 20 or more
# connections will be blocked for 5 mins.
/usr/bin/netstat -n \
        | grep tcp | awk '{print $5}' \
        | awk -F: '{print $1}' | sort | uniq -c \
        | awk '$1 > 20 {print $2}' \
        | while read i ; do
                echo Temporarily blocking $i >> /tmp/csf.log
                /usr/sbin/csf -td $i 300
        done