When setting LF_MODSEC to 3 (for example), does that mean the offending IP is blocked if the *same* modsec rule is matched 3 times, or does it mean the IP is blocked on the 3rd match of *any* modsec rule?
Thanks for any clarification you can provide!
Search found 2 matches
- 23 Jun 2020, 15:43
- Forum: General Discussion (csf)
- Topic: LF_MODSEC usage
- Replies: 1
- Views: 2270
- 10 Feb 2016, 13:45
- Forum: Suggestions (csf)
- Topic: PORTFLOOD not working with hitcount > 20
- Replies: 4
- Views: 9062
Re: PORTFLOOD not working with hitcount > 20
I am also still having this problem in CSF v8.12. I have the PORTFLOOD set to: "22;tcp;15;120,80;tcp;30;5" and I had a DoS attack on one of my customer sites, generating a "high load" notification from the server. I checked the logs for that customer account and it showed about 6...