• Debian 11 is approaching its end-of-life (vendor EOL date - August 31, 2026). Plesk Obsidian 18.0.80 will be the last release to support it.
    If you are running Plesk Obsidian on Debian 11, we recommend you upgrade those servers to Debian 12 using our dist-upgrade tool.
  • We plan to deprecate and remove the support for XML RPC protocol versions earlier than 1.6.9.1 in Plesk Obsidian 18.0.82. We strongly recommend that you update all existing integrations using earlier versions of the XML RPC protocol to comply with the version 1.6.9.1 specification.

Firewall configuration from the command-line

Azurel

Silver Pleskian
Hello,

I use plesk 11.5.30. Its possible to add firewall rules with command-line? What I do:

I use cron.hourly to download a TOR ip list and add it to apache and restart apache... working fine, but with little problems:

1. This will apache restart every hour and visitors get a error page, when apache restarts. Not fine!
2. Not all processes going down correctly. I get more and more ghost php processes after every hour.

Better, I can add tor ip list directly to the firewall. But how?


EDIT:

We know the need for firewall command line, but we don't have it yet
Thats now two years ago. Any progress?


EDIT2:

Its possible to add a rule with a description and delete all rules with a specific description?
Or add a rule for a defined time? Like a "timeban"-function.
 
Last edited:
Looks great! The features list is impressive! Its a little expensive for my small server. What server-performance lose have this extra addon? ;)

Its look like the best addon for plesk... but I have my problems with not approved external software. Its always a security risk, like browser addons. Can anybody give a statement to this addon? Have anybody use it?
 
What server-performance lose have this extra addon? ;)

There is little overhead even with a few thousand iptables rules. You can set a threshold for the maximum number of permanently / temporarily denied IP addresses and the login failure daemon will automatically rotate blocks when it reaches your maximum. Also the login failure daemon uses very little resources even when monitoring 300+ domains.
If you have any other questions just let me know :)
 
Back
Top