Re: [users@httpd] How do I choose the best settings for the Apache Server?

2023-09-16 Thread Jason Long
Hello, In the Apache configuration file, there is the following text: DO NOT EDIT. AUTOMATICALLY GENERATED.  USE INCLUDE FILES IF YOU NEED TO MAKE A CHANGE ... #/etc/apache2/conf.d/includes/pre_main_global.conf #/etc/apache2/conf.d/includes/pre_virtualhost_global.conf #/etc/apache2/co

Re: [users@httpd] realtime protection against cloud scans

2023-09-16 Thread metaed
Marc wrote: > I still need to get familiar with nft. Currently I am using ipset NFT has an equivalent -- also called a set. Here are excerpts from my configuration that show how addresses and ranges appear in a set and how a set is blocked. Defining the set of real-time intrusions: set S

RE: [users@httpd] realtime protection against cloud scans

2023-09-16 Thread Marc
> > using the NTP firewall > > Sorry, using the NFT firewall. > I still need to get familiar with nft. Currently I am using ipset, adding ip's with scripts. But ipset is preconfigured for specific netmask /24 /X. So at some point your /24 is getting full with 65k entries. It would be nice if

Re: [users@httpd] realtime protection against cloud scans

2023-09-16 Thread metaed
metaed borked: > using the NTP firewall Sorry, using the NFT firewall. - To unsubscribe, e-mail: users-unsubscr...@httpd.apache.org For additional commands, e-mail: users-h...@httpd.apache.org

Re: [users@httpd] realtime protection against cloud scans

2023-09-16 Thread metaed
Marc wrote: > Anyone having a suggestion on how to block cloud crawlers/bots? Obviously I > would like search engine bots to have access, but all the other crap I want to > lose. Only 'real users'. I take a three-pronged approach, using the NTP firewall and some scripts. 1. db-ip.com keeps a list