Imunify360 & LFD

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • ray
    Senior Member
    Forum ExplorerTechnical AssociateSolutions Developer
    • Mar 2021
    • 108

    #1

    Imunify360 & LFD

    One thing thats preventing us from testing Imunify360 on more servers is that we really depend on LFDs (part of ConfigServer Firewall) AUTHRELAY, LOCALRELAY and LOCALHOSTRELAY tracking to monitor for spammers, which is particularly useful on older servers where customer web applications may not always be up to date.

    Id like to use Imunify360s herd firewall, but still use LFD for monitoring of spammers.

    Is there any way to make these play nicely together?
  • iseletsk
    Senior Member
    • Dec 2017
    • 1199

    #2
    Our next version of Imunify360 (around a month from now) should integrate nicely with LFD/CXS. This way you will be able to get the best of both worlds.

    Comment

    • admin
      Member
      • Mar 2018
      • 52

      #3
      That sounds great. Looking forward to it!

      Comment

      • chris
        Junior Member
        • Apr 2017
        • 20

        #4
        Do you by the way plan features like this ?
        Usually (90% - 10% its phishing) when an account gets infected/hacked bots or malicious users are uploading mail scripts. And the usual Top #1 problem for us (My personal opinion of course) is dealing with outgoing mail spam.

        CSF/LFD notifies us when someone / some script is sending mass mails (variable to send alert after x mails), localrelay, authrelay, and when the queue is above x limit.

        When I get the warning I know something is wrong and start investigation. If not, usual outcome is server IP blacklisted in multiple RBLs -and other users cant send mails-, abuse mails from datacenters, IP block, or whole server block (for one account). So I believe its crucial to know whats happening with outgoing mails and queues.

        Comment

        • dev
          Junior Member
          • Apr 2017
          • 3

          #5
          We are eager to go full throttle on Imunfiy360 if and when:

          - it is fully integrated with CSF
          - those exciting features like Malware Detection and Intrusion Detection and Protection System are functional
          - it is able to give you more incident report that you can actually use
          - and Web Applications Sandboxing

          If Imunify360 can come out with these, it will be the ultimate game-changer.
          I guess that these will be available with next release and looking forward to that.

          Comment

          • admin
            Member
            • Mar 2018
            • 52

            #6
            I was informed by email that Imunify360 now supports CSF integration, however I dont see a way to switch back to using it.

            Is the only way to uninstall Imunify360, reactivate CSF, and then reinstall Imunity360 to get the CSF integration working?

            Comment

            • admin
              Member
              • Mar 2018
              • 52

              #7
              > I was informed by email that Imunify360 now supports CSF integration, however I dont see a way to switch back to using it.
              >
              > Is the only way to uninstall Imunify360, reactivate CSF, and then reinstall Imunity360 to get the CSF integration working?

              Hi! Since version 1.1.3 if user has Imunify360 agent running, he can just start csf (csf -e) and in about 30 seconds imunify360 will switch to csf integration mode. To check it, user can visit Firewall->White list page of Imunify360 UI and check if there is a "White list management disabled" warning.

              Comment

              • admin
                Member
                • Mar 2018
                • 52

                #8
                Great, that worked. Support had told me to re-install which I thought was likely unnecessary.

                Comment

                • admin
                  Member
                  • Mar 2018
                  • 52

                  #9
                  Can you clarify exactly how the CSF integration works?

                  CSF/LFD takes back over as the main firewall and Imunify just handles your gray listed IPs for herd protection?

                  Comment

                  • admin
                    Member
                    • Mar 2018
                    • 52

                    #10
                    > Can you clarify exactly how the CSF integration works?
                    >
                    > CSF/LFD takes back over as the main firewall and Imunify just handles your gray listed IPs for herd protection?

                    Yes, CSF acts as primary firewall and Imunify360 only maintains gray list. You can get more details here https://docs.imunify360.com/index.ht...ntegration.htm

                    Comment

                    • 2webmaster
                      Senior Member
                      Forum ExplorerTechnical AssociateSolutions Developer
                      • Mar 2021
                      • 101

                      #11
                      > Our next version of Imunify360 (around a month from now) should integrate nicely with LFD/CXS. This way you will be able to get the best of both worlds.

                      I see no mention of integration with CXS. Has this been accomplished?

                      Thanks

                      Comment

                      • 2webmaster
                        Senior Member
                        Forum ExplorerTechnical AssociateSolutions Developer
                        • Mar 2021
                        • 101

                        #12
                        > I see no mention of integration with CXS. Has this been accomplished?

                        No integration with CXS is planned as imunify360 has all features CXS does.

                        Comment

                        • 2webmaster
                          Senior Member
                          Forum ExplorerTechnical AssociateSolutions Developer
                          • Mar 2021
                          • 101

                          #13
                          It would be nice for Immunify360 to have a CSF and CXS uninstall option. Once hosting companies like us are comfortable that I360 is on par with CSF triggers, alerts, etc. that we can sundown CSF and CXS.

                          Comment

                          Working...