• Our team is looking to connect with folks who use email services provided by Plesk, or a premium service. If you'd like to be part of the discovery process and share your experiences, we invite you to complete this short screening survey. If your responses match the persona we are looking for, you'll receive a link to schedule a call at your convenience. We look forward to hearing from you!
  • We are looking for U.S.-based freelancer or agency working with SEO or WordPress for a quick 30-min interviews to gather feedback on XOVI, a successful German SEO tool we’re looking to launch in the U.S.
    If you qualify and participate, you’ll receive a $30 Amazon gift card as a thank-you. Please apply here. Thanks for helping shape a better SEO product for agencies!
  • The BIND DNS server has already been deprecated and removed from Plesk for Windows.
    If a Plesk for Windows server is still using BIND, the upgrade to Plesk Obsidian 18.0.70 will be unavailable until the administrator switches the DNS server to Microsoft DNS. We strongly recommend transitioning to Microsoft DNS within the next 6 weeks, before the Plesk 18.0.70 release.
  • The Horde component is removed from Plesk Installer. We recommend switching to another webmail software supported in Plesk.

Question If we Upgrade from 12.5 to Onyx How to setup firewall with Cloudflare

daedparrotsoftware

New Pleskian
We currently have a dedicated Centos 7.5 server running Plesk Parallels 12.5 and hosting a few wordpress sites.
We also have the server behind the CloudFlare CDN & Cloudflare DNS and Firewall.
This has worked great for controlling malicious traffic, but we still had some attacks coming straight to the server (bypassing cloudflare).

So, we created an iptables firewall that uses a whitelist - basically DROPS all services and ports for anything - any IP - not whitelisted, instead of using Blacklists.
We whitelist all the CloudFlare network IP's, and a few other IP's like our own, wordfence, paypal, and so on.

This approach is faster and works better than blocking 'blacklists' - which can get huge. (In fact, we are creating a bash script - a template - so anyone who wants to, can do this (which I will post somewhere here so people can use/critique).

NOW, the question: I know that - according to a Plesk engineer - Onyx has it's own firewall system - psa-firewall - and does NOT use iptables.
So, CAN we, and HOW do we, use the Onyx firewall to accomplish the same thing as I outlined above?

The docs are a bit...sparse on the Onyx firewall. I am trying to get help/information BEFORE taking that upgrade step, because going back, would be incredibly...painful. :)

My thanks, for any and all help.

Sid

NOTE - we tried fail2ban and the Plesk 12.5 firewall. Could NOT get it to do quite the same job, and performance took a nose dive shortly after implementation, mostly due to Fai2Ban jails and a LOT of blacklist IP's.
 
Back
Top