Portal Home > Knowledgebase > Articles Database > how to allow Dynamic DNS in CSF firewall
how to allow Dynamic DNS in CSF firewall
Posted by crazyaboutlinux, 03-30-2010, 02:05 AM |
HI
How to Allow Dynamic DNS IP addresses - always allow your IP address even if it changes whenever you connect to the internet
we are using
cPanel 11.25.0-R43473
WHM 11.25.0 - X 3.9
CENTOS 5.4 i686 virtuozzo
And csf: v5.00
|
Posted by madaboutlinux, 03-30-2010, 03:31 AM |
What exactly are you upto? If you have a dynamic IP from your ISP and you would like to restrict server access to your yourself, you can allow the specific subnet in the CSF firewall.
|
Posted by Sileep Kumar M S, 03-30-2010, 03:45 AM |
You may try whitelist the IP range.
|
Posted by assistanz247, 03-30-2010, 04:03 AM |
Hello,
Yes you can allow a set of IP addresses by adding CIDR in your whitelist. For example if you want to allow 72.30.2.43 range then go to whois.is and put the IP address and search you will get a result like,
NetRange: 72.30.0.0 - 72.30.255.255
CIDR: 72.30.0.0/16
just open your csf.allow file and add,
72.30.0.0/16
This will allow the whole range.
|
Posted by crazyaboutlinux, 03-30-2010, 05:33 AM |
I will try it meantime can you please tell what is this option
|
Posted by madaboutlinux, 03-30-2010, 05:39 AM |
The following URL should make things clear for you:
http://forum.configserver.com/showthread.php?t=811
|
Posted by assistanz247, 03-30-2010, 05:39 AM |
Hello,
Its clearly mentioned in CSF documentation as,
# If you wish to allow access from dynamic DNS records (for example if your IP
# address changes whenever you connect to the internet but you have a dedicated
# dynamic DNS record from the likes of dyndns.org) then you can list the FQDN
# records in csf.dyndns and then set the following to the number of seconds to
# poll for a change in the IP address. If the IP address has changed iptables
# will be updated.
#
# A setting of 600 would check for IP updates every 10 minutes. Set the value
# to 0 to disable the feature
DYNDNS =
I hope its clear now.
|
Posted by crazyaboutlinux, 11-25-2010, 09:03 AM |
Can i example.com domain into csf.dyndns file which is hosted on the server
Other IPs are also blocking frequently in temporary IP entries file & then it will be permanently blocked, how do i prevent this ??
IP address A/D Port Dir Time To Live Comment
202.131.97.2? DENY 202.XXX.XX.X * in 28m 31s lfd - *Port Scan* detected from 202.XXX.XX.X (IN/India/-). 11 hits in the last 65 seconds
202.131.104.41? DENY 202.XXX.XXX.XX * in 28m 56s lfd - *Port Scan* detected from 202.XXX.XXX.XX (IN/India/-). 11 hits in the last 90 seconds
202.131.97.190? DENY 202.XXX.XX.XX * in 29m 42s lfd - *Port Scan* detected from 202.XXX.XX.XX (IN/India/-). 11 hits in the last 136 seconds
|
Add to Favourites Print this Article
Also Read