Basic Question about Blocking Access to the WHM and CPanel Pages
I have of course created a hostname for my WMH/cPanel server in the form something.mydomain.com and only access WMH and cPanel through the ports 2087 and 2083. All of my sites also are proxied through a firewall so that no traffic needs to ever hit ports 80 and 443 directly to the hostname. Does it make sense for me to block access to the server for ports 80 and 443 except to the the CIDR ranges for those firewalls (which can send traffic through either of those ports)? I ask because I see traffic being blocked by Modsecurity rules coming directly into the hostname.
-
Hey there! This might cause some issues with the free SSL that is provided for the hostname as the verification checks for that certificate do happen over a web connection. However, we do have a list of IPs for that particular traffic you could allow through the firewall if you can configure that: 0 -
The site is already behind Sucuri, but would it make sense to just lock down the countries using CSF country code blocks and my Maxminds API license? It is easy to lock down the most frequent offenders. 0 -
Sure - you could try that instead - as long as everything connects properly for AutoSSL that will still work. 0
Please sign in to leave a comment.
Comments
3 comments