Portal Home > Knowledgebase > Articles Database > how to allow Dynamic DNS in CSF firewall


how to allow Dynamic DNS in CSF firewall




Posted by crazyaboutlinux, 03-30-2010, 02:05 AM
HI How to Allow Dynamic DNS IP addresses - always allow your IP address even if it changes whenever you connect to the internet we are using cPanel 11.25.0-R43473 WHM 11.25.0 - X 3.9 CENTOS 5.4 i686 virtuozzo And csf: v5.00

Posted by madaboutlinux, 03-30-2010, 03:31 AM
What exactly are you upto? If you have a dynamic IP from your ISP and you would like to restrict server access to your yourself, you can allow the specific subnet in the CSF firewall.

Posted by Sileep Kumar M S, 03-30-2010, 03:45 AM
You may try whitelist the IP range.

Posted by assistanz247, 03-30-2010, 04:03 AM
Hello, Yes you can allow a set of IP addresses by adding CIDR in your whitelist. For example if you want to allow 72.30.2.43 range then go to whois.is and put the IP address and search you will get a result like, NetRange: 72.30.0.0 - 72.30.255.255 CIDR: 72.30.0.0/16 just open your csf.allow file and add, 72.30.0.0/16 This will allow the whole range.

Posted by crazyaboutlinux, 03-30-2010, 05:33 AM
I will try it meantime can you please tell what is this option

Posted by madaboutlinux, 03-30-2010, 05:39 AM
The following URL should make things clear for you: http://forum.configserver.com/showthread.php?t=811

Posted by assistanz247, 03-30-2010, 05:39 AM
Hello, Its clearly mentioned in CSF documentation as, # If you wish to allow access from dynamic DNS records (for example if your IP # address changes whenever you connect to the internet but you have a dedicated # dynamic DNS record from the likes of dyndns.org) then you can list the FQDN # records in csf.dyndns and then set the following to the number of seconds to # poll for a change in the IP address. If the IP address has changed iptables # will be updated. # # A setting of 600 would check for IP updates every 10 minutes. Set the value # to 0 to disable the feature DYNDNS = I hope its clear now.

Posted by crazyaboutlinux, 11-25-2010, 09:03 AM
Can i example.com domain into csf.dyndns file which is hosted on the server Other IPs are also blocking frequently in temporary IP entries file & then it will be permanently blocked, how do i prevent this ?? IP address A/D Port Dir Time To Live Comment 202.131.97.2? DENY 202.XXX.XX.X * in 28m 31s lfd - *Port Scan* detected from 202.XXX.XX.X (IN/India/-). 11 hits in the last 65 seconds 202.131.104.41? DENY 202.XXX.XXX.XX * in 28m 56s lfd - *Port Scan* detected from 202.XXX.XXX.XX (IN/India/-). 11 hits in the last 90 seconds 202.131.97.190? DENY 202.XXX.XX.XX * in 29m 42s lfd - *Port Scan* detected from 202.XXX.XX.XX (IN/India/-). 11 hits in the last 136 seconds



Was this answer helpful?

Add to Favourites Add to Favourites    Print this Article Print this Article

Also Read
Hostfresh server down? (Views: 768)
Rapidswitch down? (Views: 758)


Language: