Running AlmaLinux v8.10.0 STANDARD kvm on a VPS. CPanel version 130.0.3
A new problem popped up in the past month.
At some time in the past, my home IP address got blocked for too many failed logins (from Apple Mail retrying multiple email addresses). I used csf (v14.24) to unblock and whitelist the IP address. That worked fine for a long time. Then out of the blue (or at least I am not aware of any change I made that would cause it) when I rebooted the VPS, my IP address was again locked out of http access on all my websites. I was able to use a VPN to log back into WHM and restart the firewall using csf and then I could access my websites and WHM again from my home IP–the whitelist was in effect again after restarting the firewall. Ever since, every time I reboot, I have to restart the firewall to activate the whitelist to let my home IP address back in.
My home IP is not static and is through xfinity, so a VPN is the only way I can change my IP address. Rebooting the router doesn’t change the home IP address.
It seems as if there is a conflict happening where the whitelist from csf isn’t loading on reboot, or it’s loading and then something else loads after and clobbers it. Are there conflicting rules somewhere? Is something loading in the wrong order? Do I have two competing firewalls running?
One thing I noticed is that the /etc/firewalld/firewalld.conf has FirewallBackend=nftables, but in csf it talks only about iptables. Is csf just a frontend for firewalld? In which case could that be the source of the conflict?
I had a lot of *nix experience decades ago, so I’m familiar with the basics, but I’m not current on how firewalls work. I’m not sure where to start to troubleshoot this.
Thanks in advance for any help.