×

Warning

JUser: :_load: Unable to load user with ID: 43

JUser: :_load: Unable to load user with ID: 40

Security

Here you can set up a simple iptables firewall directly from the web interface of the application. For security reasons, this configuration can be carried out only by the administrator with the Master admin status.

 

You can add individual IP addresses or whole ranges (e.g. 192.168.123.0/24).
For each IP address, you can individually allow or forbid the following services: HTTP, HTTPS, SSH, SMTP, POP3, IMAP, FTP, MySQL, Syslog and PING.
You can change the status to allowed/forbidden by clicking on icon check ko/icon check ok.

In the last line (Global), you can modify the default settings for individual services. For example, it is possible to forbid SSH globally or allow it only from predefined IP addresses.

 

Furthermore, it is possible to allow or forbid a different port from the predefined ones. You may add up to 5 rules of your own in the firewall settings, which you can then allow or forbid. This option is useful especially when ssh uses a different port from the standard one and you want it to be protected by the firewall. 

If you want to edit a particular manually added rule (a column in the firewall), you have to click on a given column in the header and change the rule.

A rule can be removed by entering “0” into the port number field.

 

Activate

If you click on this button, the firewall settings will be updated within 5 minutes. If you do not click on it, no changes will be made to the FW and you can continue setting things up.

If there are no IP addresses in the firewall, the function will not be activated. This option makes it possible for you to disable the FW that is automatically set up by the system and set up an individual FW at the level of the operating system.

You define rules according to your own requirements. At the very least, the following three public IP addresses should be allowed for technical support purposes:

  • 95.173.194.62 (Our office)
  • 95.173.193.40 (VPN server)
  • 95.173.193.60 (Main server)

 

icon info2 More about system security here.

 

System back-ups

ISPadmin has an automatic data back-up functionality. It is possible to store...

MySQL database

Restart of MySQL service /etc/init.d/mysqld restart Recovery of database...

ISPadmin update

Switch to new system version using the following command from command line (logi...

Postfix mail server

By default, the SMTP server is configured in the way that it is only possible...

System Variables

System variables are used for replacing items such as client's name, address,...

System migration

The information contained in this manual pertains to the migration of ISPadmin ...

Emails cannot be sent because of their size

Check and modify the settings of the following parameters: upload_max_f...

Ramdisk and RRD backup-data restoration

More on RAM disk here (index.php?option=com_content view=article id=508:4-11-bet...

HTTPS Certificates

These are instructions on how to create and set up trustworthy certificates (h...

Crashed table repair

these instructions (index.php?option=com_content view=article id=1284:system-bac...

Moving graphs to RAMDISK

The main usage load for disks, on which the system is installed on, is the gener...

Forgotten root password

You can try two ways: First procedure 1. Insert installation DVD of ISPa...

Text editors

Nano text editor is always used in this documentation. If you don’t...

Linux update

For reasons of compatibility and availability of future versions of ISPadmin,...

ISPadmin serving as SMTP server

By default, the SMTP server is configured in the way that it is only possible to...

Cache-only DNS server

Caching-only is ready after installation of ISPadmin. It is sufficient to use IP...

Technical support status cannot be verified

If technical support cannot be verified, most likely it is due to DNS malfunc...

Administration of running processes

We recommend using htop program for easier monitoring of running process inst...

Timezone settings

"Europe/Prague” timezone is set by default. To change it, do the following:...

IPv6

ISPadmin does not currently support IPv6, it only supports IPv4. It is, of cours...

Configuration / update of IP Address

A) Temporary setting of IP address (until next Linux restart).Just add the fo...

High CPU load of ISPadmin server

Run htop command from the Linux console to determine the problems. With this ...

ISPadmin operation behind NAT

If you have your ISPadmin located on private network and wish to access it from ...

Manual update

If the Error 404: Not Found message appears during an update, it will be necessa...

Inner/outer address on ISPadmin server

The system is typically connected to the network by one network card only. Both ...

Running service check

If you need to find out if a certain process is running use the following comman...

Error "Allowed memory size of ... bytes exhausted ..."

Fatal error: Allowed memory size of ... bytes exhausted (tried to allocate ... b...

What is the directory structure in /usr/local/script/ispadmin/rrd_data?

headend ipaccount modem routers snmp switches user_devices wifi

«
»

CONTACT

NET service solution, s.r.o.
Žerotínova 3056/81a
787 01 Šumperk
Czech Republic