Hi,
I am trying to monitor a problematic firewall on a fully up to date FreePBX 15.0.16.72 virtual machine but unsure how to do so.
I am using a CheckMK agent to monitor lots of items including Systemd Service Summary
Every few days we start getting hundreds of Fail2Ban emails and when we log into the PBX we see the System Firewall is disabled. CheckMK [Systemd Service Summary] still shows the same information as when the firewall was enabled.
OK - 108 services in total, 15 disabled services
I have read other forum ports about checking the firewall and iptables service so I have started trying to run manual commands to see what results I get.
On a fresh reboot of FreePBX, it shows the System Firewall and Firewall Config both have green ticks in the dashboard, however if I run these commands I get the results below them
service firewalld status
Active: inactive (dead)
service iptables status
Active: inactive (dead)
service fail2ban status
Active: active (running)
service freepbx status
Active: active (exited)
Q1 - How can firewalld and iptables be inactive (dead) if the firewall is working correctly?
fwconsole firewall stop - the firewall stops and the pbx is accessable
fwconsole firewall start - the firewall starts and the pbx is secured again
service firewalld status - Active: inactive (dead)
service iptables status - Active: inactive (dead)
If I disable and enable the firewall via the GUI then we get -
service firewalld status - Active: inactive (dead)
service iptables status - Active: active (exited)
if I run service firewalld stop
and then service firewalld start
Redirecting to /bin/systemctl start firewalld.service
we get
Firewall Rules corrupted! Restarting in 5 seconds
More information available in /tmp/firewall.log
But finally we have
service firewalld status - Active: active (running)
When I look at the firewall log I can see
'Firewall Rules corrupted! Restarting in 5 seconds
No fpbx-rtp in ipv6
Could this be why the firewall keeps disabling itself every few days? Sorry im a bit stuck.
I have lots of other FreePBXs and PBXacts running with no issues and I may even just rebuild this one, but I would like to learn how to fix it rather than just rebuild.
Any help would be greatly appreciated,
Sorry this is a bit rushed, I can add more detail if needed in the next few days.
Thx
Dave