CSF/LFD

From Leo's Notes
Revision as of 22:00, 1 December 2019 by Leo (talk | contribs)
This page was last edited on 1 December 2019, at 22:00.

Logging

CSF/LFD automatically logs to /var/log/lfd.log.

# tail /var/log/lfd.log

Quick Usage

Task Command
Deny IP
# csf -d <IP>
Allow IP
# csf -a <IP>
Remove Denial
# csf -dr <IP>
Remove Allow
# csf -ar <IP>
Temporary Denial
# csf -td <IP> <seconds>


Automatic Temporary Bans

Ghetto script to quickly block clients making excessive connections:

#!/bin/bash

# Any clients connecting to the server resulting in 20 or more
# connections will be blocked for 5 mins.
/usr/bin/netstat -n \
        | grep tcp | awk '{print $5}' \
        | awk -F: '{print $1}' | sort | uniq -c \
        | awk '$1 > 20 {print $2}' \
        | while read i ; do
                echo Temporarily blocking $i >> /tmp/csf.log
                /usr/sbin/csf -td $i 300
        done