Skip to main content

Using cPHulk and CSF Together?

Comments

6 comments

  • danielpmc
    Hello sahostking, Wow! Your cpHulk is working really well judging by your logs. I am curious about your settings. Do you have cpHulk set at default settings or have you altered them? If you altered them could you share your settings with us? I ask this because my cpHulk sits like a lump on a log. Nothing happens. But when i look at my CSF logs i nail the nefarious #$#$*. to the wall. My CSF blocks SSH, Exim and FTP abusers everyday, yet cpHulk does not hardly ever block anything.
    Do you guys recommend we still stick with CSF and just find the cause or is using both better now?

    In my opinion i would rely on both services, simply because two security guards are better than one. Besides i could not imagine running a server(s) without a Firewall. danielpmc
    0
  • sahostking
    Naaa just started it. No changes whatsoever. I'm thinking of adding this to command text "csf --tempdeny %remote_ip% 3600" Then when bruteforce is picked up with Cphulk it does not block there but rather in CSF? Anyone know if this will work well. Going to test it shortly though.
    0
  • sahostking
    a ha - got it working :)
    0
  • cPanelMichael
    I'm thinking of adding this to command text "csf --tempdeny %remote_ip% 3600" Then when bruteforce is picked up with Cphulk it does not block there but rather in CSF? Anyone know if this will work well.

    Yes, this should work as expected. However, you may want to disable "Block IP addresses at the firewall level if they trigger brute force protection" in your cPHulk configuraiton to avoid duplicate blocks of the IP address at the firewall level. Thank you.
    0
  • sahostking
    Yip did that already thanks
    0
  • Medical Websites
    Glad I found this thread. Just had the support people at our hosting provider tell me to turn off cPhulk because I am already using csf and it therefore isn't needed. This came after I posed a question about why cPhulk was spawning lots of processes, adding to server load, which, to me suggested there were just a lot of brute force attacks that csf wasn't detecting (our servers are also supposedly protected by their hardware firewall). Pleased I trusted my own instincts on this and did my own searches, and maybe time to look for another provider.
    0

Please sign in to leave a comment.