Symptoms
On systems using nftables, rules added with Host Access Control in WHM are ignored when another firewall application, such as Imunify360 or CSF, is installed.
Cause
Firewall rules are processed one at a time, in order. Once a packet has been matched to a rule, no further rules are processed for that packet. Other firewall applications place their rulesets ahead of the Host Access Control ruleset. Since other firewalls are typically designed to be the only firewall on a server, they have explicit allow rules for each open port after any defined deny rules. As the connection is then allowed in these other rulesets, the relevant Host Access Control ruleset is never called and the connection is allowed.
Resolution
Use the other installed firewall application to manage access to the server.
Comments
0 comments
Article is closed for comments.