Whitelist Firewall Setup issue

All installation and configuration problems and questions

Moderators: gerski, enjay, williamconley, Op3r, Staydog, gardo, mflorell, MJCoate, mcargile, Kumba, Michael_N

Whitelist Firewall Setup issue

Postby jlam » Mon Dec 23, 2024 9:13 am

Hello all,
Brand new Vicibox 11 install:
Locked myself out trying to enable the whitelist:
Steps taken:
Enabled the IP list in Admin- System settings
Added ips to the whitelist and enabled the whitelist

Commented out the 2 default crontab entries and added these:
@reboot /usr/bin/VB-firewall --white --quiet
* * * * * /usr/bin/VB-firewall --white --quiet

Set etho to public in yast and removed all services except ssh
As soon as the crontab ran it locked me out
Server is hosted with a static ip for - single server no cluster
Had the host comment out crontab lines and reboot the server which gave me access again- also added back in the default services in the public zone and restarted the firewall
Not sure what to do next to implement without locking myself out - Also confirmed that my ip was in the whitelist
Any advice is appreciated!
Thank you

Vicidial: VERSION: 2.14-933a BUILD: 241208-1747
Vicibox v.11.0
openSUSE Leap 15.5
Linux 5.14.21-150500.55.12-default
jlam
 
Posts: 4
Joined: Mon Dec 23, 2024 8:01 am

Re: Whitelist Firewall Setup issue

Postby carpenox » Mon Dec 23, 2024 2:15 pm

I havent updated this in a while, i probably need to but this should give you some guidance


https://dialer.one/index.php/how-to-sec ... ly-part-1/
Alma Linux 9.5 | SVN Version: 3920 | DB Schema Version: 1725 | Asterisk 18.26.0 | PHP8
https://dialer.one -:- 1-833-DIALER-1 -:- https://linktr.ee/CyburDial -:- WA: +19549477572
DC: https://discord.gg/DVktk6smbh -:- TG: https://t.me/+wkDmkF9U4aUxOGYx
carpenox
 
Posts: 2584
Joined: Wed Apr 08, 2020 2:02 am
Location: St Petersburg, FL

Re: Whitelist Firewall Setup issue

Postby williamconley » Fri Dec 27, 2024 12:46 am

Note that while testing, it can be useful to use "screen" to run a "sleep 600; reboot" and then leave that screen running (detach from it). Then you do NOT use the crontab firewall entries, just run them manually from the CLI.

Result: if you lock yourself out, the system reboots in 10 minutes and does not run the firewall. So you can go get a soda and try again in a few minutes. Without the Embarrassing Moment with the hosting provider.

Also a great reason to run a Sandbox Vicidial in a VM. So you can practice this sort of thing (and MANY others) with zero effect on any live server(s).
Vicidial Installation and Repair, plus Hosting and Colocation
Newest Product: Vicidial Agent Only Beep - Beta
http://www.PoundTeam.com # 352-269-0000 # +44(203) 769-2294
williamconley
 
Posts: 20415
Joined: Wed Oct 31, 2007 4:17 pm
Location: Davenport, FL (By Disney!)


Return to Support

Who is online

Users browsing this forum: No registered users and 66 guests