CSF/LFD
From Leo's Notes
This page was last edited on 1 December 2019, at 22:00.
Logging
CSF/LFD automatically logs to /var/log/lfd.log.
# tail /var/log/lfd.log
Quick Usage
| Task | Command |
|---|---|
| Deny IP | # csf -d <IP>
|
| Allow IP | # csf -a <IP>
|
| Remove Denial | # csf -dr <IP>
|
| Remove Allow | # csf -ar <IP>
|
| Temporary Denial | # csf -td <IP> <seconds>
|
Automatic Temporary Bans
Ghetto script to quickly block clients making excessive connections:
#!/bin/bash
# Any clients connecting to the server resulting in 20 or more
# connections will be blocked for 5 mins.
/usr/bin/netstat -n \
| grep tcp | awk '{print $5}' \
| awk -F: '{print $1}' | sort | uniq -c \
| awk '$1 > 20 {print $2}' \
| while read i ; do
echo Temporarily blocking $i >> /tmp/csf.log
/usr/sbin/csf -td $i 300
done