0

I'm pretty new to PSAD but eagerly getting into it to have a safer installation. But some understanding is missing

I've had yesterday the following notification :

[psad-status] removed iptables block against xxx.xxx.xxx.xx

It was an automatic notification, my problem right here is that there is no particular reason that I understand so far that would white-list automatically an IP

This is quite a problem as I'd like to rely on a strict behaviour, but without understanding well what happened, can't be sure about it. Nothing accurate found googling about this specific one

Thanks a lot for your help

Ben
  • 113
  • 1
  • 9

2 Answers2

0

It didn't whitelist that IP, it merely unblacklisted it. Presumably it did so because a previous time-based block expired. The documentation, or more detailed logging, may provide you with more information about exactly what happened in this particular instance.

womble
  • 95,029
  • 29
  • 173
  • 228
0

That message is caused by an address being removed from the blacklist because it has reached the timeout limit.

AUTO_BLOCK_TIMEOUT

Defines the length of time that an auto-generated block rule will remain in effect (ENABLE_AUTO_IDS must be set to "Y" for this keyword to be used). The default is "3600" seconds (one hour).

user9517
  • 114,104
  • 20
  • 206
  • 289