General Discussion of atomic repo and development projects.
Ask for help here with anything else not covered by other forums.
aus-city
Forum Regular
Posts: 685 Joined: Thu Oct 26, 2006 11:56 pm
Unread post
by aus-city » Fri Nov 16, 2007 2:55 am
Scott,
If there are IPs in the block list and either you restart the server, ASL, or psa, you end up having stray old IP addresses listed from ages ago.
I know you can edit the file on the server and remove them, but can you add a clear in the block list to flush the file clean?
Thanks!
zeki
Forum Regular
Posts: 120 Joined: Sat Aug 12, 2006 8:14 am
Unread post
by zeki » Fri Nov 16, 2007 8:24 pm
i reported this too to support..... same here...
scott
Atomicorp Staff - Site Admin
Posts: 8355 Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:
Unread post
by scott » Fri Nov 16, 2007 11:07 pm
yep, the case you started is already open. This way we can tie multiple people together, and it raises the priority of a bug report or a feature request.
aus-city
Forum Regular
Posts: 685 Joined: Thu Oct 26, 2006 11:56 pm
Unread post
by aus-city » Sat Nov 17, 2007 2:32 am
Perfect Scott, so now there are two against this case?
Thanks!
zeki
Forum Regular
Posts: 120 Joined: Sat Aug 12, 2006 8:14 am
Unread post
by zeki » Sat Nov 17, 2007 3:23 am
workarround from support:
The list is located in /var/ossec/var/, you can clear that file out
with:
cp /dev/null /var/ossec/var/block-list
clear the firewall rules with:
/etc/init.d/iptables restart
and clear /etc/hosts.deny with
cp /dev/null /etc/hosts.deny
greets
zwki
scott
Atomicorp Staff - Site Admin
Posts: 8355 Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:
Unread post
by scott » Sat Nov 17, 2007 9:34 am
yep exactly, the case management system automatically ranks issues and reports them daily to management. On my side Ive (almost) got that tied into the source code management system, so when you update a bug it actually updates the case and can even notify the case holders (you two) that its been fixed automatically.
mrwilson
Forum User
Posts: 53 Joined: Sat Jun 07, 2008 11:09 pm
Unread post
by mrwilson » Wed Aug 20, 2008 10:44 am
Should the Plesk GUI block list tab be showing all the blocked IPs that my BFD has collected before I installed ASL?
My list is empty.
I can still see most of them in /etc/apf/deny_hosts.rules
mrwilson
now using asl-2.2-1.el5.art on Centos 5 64-bit - Plesk 9.2.2
scott
Atomicorp Staff - Site Admin
Posts: 8355 Joined: Wed Dec 31, 1969 8:00 pm
Location: earth
Contact:
Unread post
by scott » Wed Aug 20, 2008 11:07 am
It is tracking the shuns generated by the ASL active response system