- Server operating system version
- Ubuntu 18.04.6 LTS
- Plesk version and microupdate number
- Plesk Obsidian 18.0.52 Actualizació #3
Hi,
I have a problem with a production machine.
My Firewall (Plesk->Extensions->Firewall) tells me that I have to apply the changes. But when I try to it simply halts the machine (or the network, who knows) to the extend that I cannot ping it and I have to hard reset the server for it to work.
I waited some minutes, but It did not wake up.
The server contains a online store, so I cannot happily try things that halt the machine!!
Now... Right now I added some filters that try to block all access from RU, CN, PH,... so it makes sense that the process of setting up iptables with tens of thousands of rules takes its time.
But the server hanged EVEN WHEN i tried to update a VANILLA configuration to itself (yes, I checked and my original configuration was the same that the updated one).
Now IMPORTANT: I have some 15K deny rules in one Nginx configuration of one of my customers.
In fact, I pretend to move those 15K rules to a more general.... reject all traffic from RU, CN,...SO... IF Firewall is going to run, I could get rid of those rules.
Now... here it comes the question:
Does anybody can tell me if Plesk's Nginx is using IPTables to set those Deny rules? I found no place telling it, but that could explain why a Vanilla Firewall config does halt the system when upgrading with very simple rules.
I have a problem with a production machine.
My Firewall (Plesk->Extensions->Firewall) tells me that I have to apply the changes. But when I try to it simply halts the machine (or the network, who knows) to the extend that I cannot ping it and I have to hard reset the server for it to work.
I waited some minutes, but It did not wake up.
The server contains a online store, so I cannot happily try things that halt the machine!!
Now... Right now I added some filters that try to block all access from RU, CN, PH,... so it makes sense that the process of setting up iptables with tens of thousands of rules takes its time.
But the server hanged EVEN WHEN i tried to update a VANILLA configuration to itself (yes, I checked and my original configuration was the same that the updated one).
Now IMPORTANT: I have some 15K deny rules in one Nginx configuration of one of my customers.
In fact, I pretend to move those 15K rules to a more general.... reject all traffic from RU, CN,...SO... IF Firewall is going to run, I could get rid of those rules.
Now... here it comes the question:
Does anybody can tell me if Plesk's Nginx is using IPTables to set those Deny rules? I found no place telling it, but that could explain why a Vanilla Firewall config does halt the system when upgrading with very simple rules.