Dshield stopped all traffic to server

Customer support forums for Atomic Protector (formerly Atomic Secured Linux). There is no such thing as a bad question here as long as it pertains to using Atomic Protector. Newbies feel free to get help getting started or asking questions that may be obvious. Regular users are asked to be gentle. :-)
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Dshield stopped all traffic to server

Unread post by biggles »

During the night (CET) my server stopped responding on all ports. I naturally thought this was a firewall event because all other VMs on the server looked ok. I was able to log in via terminal and as soon as i reset iptables everything worked. I then started to suspect some of the blocklists. I removed them all and restored them one by one. When turning on "Dshield top attackers list" I was locked out again.

So, if you are experiencing this kind of trouble, try to remove the dshield blacklist.
scott
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 8355
Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:

Re: Dshield stopped all traffic to server

Unread post by scott »

Dshield blocks by the netblock (/24) rather than by the IP, so all it takes is for someone else on your segment to get your system as collatoral damage.
biggles
Forum Regular
Forum Regular
Posts: 806
Joined: Tue Jul 15, 2008 2:38 pm
Location: Sweden
Contact:

Re: Dshield stopped all traffic to server

Unread post by biggles »

But should the server be unreachable from both the inside and the outside if it's blocked? Shouldn't whitelisting work? I could not reach the server from any computer and the server could not communicate with the internet.

When searching for IP:s in the block I cannot find any indication of them being blacklisted.
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Dshield stopped all traffic to server

Unread post by mikeshinn »

Blacklists are applied to input and output.
Post Reply