<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Advanced Policy Firewall</title>
	<atom:link href="http://www.rfxn.com/projects/advanced-policy-firewall/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.rfxn.com</link>
	<description> Linux Software &#38; Blog</description>
	<lastBuildDate>Thu, 26 Jan 2012 07:01:13 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Peter M Abraham</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-22720</link>
		<dc:creator>Peter M Abraham</dc:creator>
		<pubDate>Thu, 19 Jan 2012 16:23:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-22720</guid>
		<description>On some servers where their DNS is shaky at start up, APF basically locks up the machine because there appears to be no time out.

Can you please put in some logic that tests to see if DNS is working the way APF needs it to start, and then skip starting (sending an email out notifying it did not start)?</description>
		<content:encoded><![CDATA[<p>On some servers where their DNS is shaky at start up, APF basically locks up the machine because there appears to be no time out.</p>
<p>Can you please put in some logic that tests to see if DNS is working the way APF needs it to start, and then skip starting (sending an email out notifying it did not start)?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-22171</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Wed, 11 Jan 2012 11:58:49 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-22171</guid>
		<description>It looks like you got some invalid entries in the APF deny file , I would recommend clearing out the file /etc/apf/deny_hosts.rules. The file should only contain IP/Host entries or commented lines prefixed with #.

rm -f /etc/apf/deny_hosts.rules
(apf will recreate it)</description>
		<content:encoded><![CDATA[<p>It looks like you got some invalid entries in the APF deny file , I would recommend clearing out the file /etc/apf/deny_hosts.rules. The file should only contain IP/Host entries or commented lines prefixed with #.</p>
<p>rm -f /etc/apf/deny_hosts.rules<br />
(apf will recreate it)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-22169</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Wed, 11 Jan 2012 11:44:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-22169</guid>
		<description>No, APF will take over from CentOS Firewall for you.</description>
		<content:encoded><![CDATA[<p>No, APF will take over from CentOS Firewall for you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Bryan Eggers</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-22168</link>
		<dc:creator>Bryan Eggers</dc:creator>
		<pubDate>Wed, 11 Jan 2012 11:36:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-22168</guid>
		<description>Using APF 9.7, when I use -r to restart I get these errors (DDOS and BFD are installed):

apf(6891): {trust} deny all to/from /usr/local/ddos/ddos.sh
iptables v1.3.5: invalid mask `ddos.sh&#039; specified

apf(19641): {trust} deny all to/from /usr/local/sbin/bfd
iptables v1.3.5: invalid mask `bfd&#039; specified

I&#039;ll buy you a couple of beers if you can help me fix this. 
Thanks</description>
		<content:encoded><![CDATA[<p>Using APF 9.7, when I use -r to restart I get these errors (DDOS and BFD are installed):</p>
<p>apf(6891): {trust} deny all to/from /usr/local/ddos/ddos.sh<br />
iptables v1.3.5: invalid mask `ddos.sh&#8217; specified</p>
<p>apf(19641): {trust} deny all to/from /usr/local/sbin/bfd<br />
iptables v1.3.5: invalid mask `bfd&#8217; specified</p>
<p>I&#8217;ll buy you a couple of beers if you can help me fix this.<br />
Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: ari</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-22110</link>
		<dc:creator>ari</dc:creator>
		<pubDate>Tue, 10 Jan 2012 18:54:37 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-22110</guid>
		<description>are i must disable centos firewall before install apf?
thanks for answer</description>
		<content:encoded><![CDATA[<p>are i must disable centos firewall before install apf?<br />
thanks for answer</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: BFD Rules for Asterisk &#124; Sean Siegel</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-21437</link>
		<dc:creator>BFD Rules for Asterisk &#124; Sean Siegel</dc:creator>
		<pubDate>Tue, 03 Jan 2012 08:01:47 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-21437</guid>
		<description>[...] a regular user of APF and BFD by RF Networks, I decided to make my own BFD scripts. I did find some very similar scripts [...]</description>
		<content:encoded><![CDATA[<p>[...] a regular user of APF and BFD by RF Networks, I decided to make my own BFD scripts. I did find some very similar scripts [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Ryan M.</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-20715</link>
		<dc:creator>Ryan M.</dc:creator>
		<pubDate>Mon, 26 Dec 2011 00:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-20715</guid>
		<description>Are there any errors that you are seeing specifically ? Please let me know and I will look into it promptly to correct it.

As for older versions of APF, I have put together a path where all previous versions can be downloaded:
http://www.rfxn.com/downloads/old/apf/

I hope this helps, thank you for your continued use of APF.</description>
		<content:encoded><![CDATA[<p>Are there any errors that you are seeing specifically ? Please let me know and I will look into it promptly to correct it.</p>
<p>As for older versions of APF, I have put together a path where all previous versions can be downloaded:<br />
<a href="http://www.rfxn.com/downloads/old/apf/" rel="nofollow">http://www.rfxn.com/downloads/old/apf/</a></p>
<p>I hope this helps, thank you for your continued use of APF.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: James</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-20713</link>
		<dc:creator>James</dc:creator>
		<pubDate>Sun, 25 Dec 2011 23:50:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-20713</guid>
		<description>Where are the old versions of all your projects? Sometimes the new versions just dont work and you need exact old versions.

 Like the syntax changes you made to current version of AFP make iptables shit itself.</description>
		<content:encoded><![CDATA[<p>Where are the old versions of all your projects? Sometimes the new versions just dont work and you need exact old versions.</p>
<p> Like the syntax changes you made to current version of AFP make iptables shit itself.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Rob</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-19871</link>
		<dc:creator>Rob</dc:creator>
		<pubDate>Thu, 15 Dec 2011 00:58:03 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-19871</guid>
		<description>Just thought I&#039;d mention a couple of the external blocklists are significantly out of date:

The Project Honey Pot blocklist (rfxn.com/downloads/php_list) doesn&#039;t appear to have been updated in some time and most of the IPs I double checked haven&#039;t seen any malicious activity in the last 3 months.

The DShield list (feeds.dshield.org/top10-2.txt) also appears to be very out of date - it has a timestamp of 1st June 2011, despite no obvious indications on their website.

They have a newer top 100 list, but they recommend using a 20 subnet blocklist instead (http://feeds.dshield.org/block.txt).


The Spamhaus list is still up to date and the reserved networks appears to be mostly correct as well (maybe a couple of entries missing).</description>
		<content:encoded><![CDATA[<p>Just thought I&#8217;d mention a couple of the external blocklists are significantly out of date:</p>
<p>The Project Honey Pot blocklist (rfxn.com/downloads/php_list) doesn&#8217;t appear to have been updated in some time and most of the IPs I double checked haven&#8217;t seen any malicious activity in the last 3 months.</p>
<p>The DShield list (feeds.dshield.org/top10-2.txt) also appears to be very out of date &#8211; it has a timestamp of 1st June 2011, despite no obvious indications on their website.</p>
<p>They have a newer top 100 list, but they recommend using a 20 subnet blocklist instead (<a href="http://feeds.dshield.org/block.txt" rel="nofollow">http://feeds.dshield.org/block.txt</a>).</p>
<p>The Spamhaus list is still up to date and the reserved networks appears to be mostly correct as well (maybe a couple of entries missing).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: New Instalation Kloxo guide &#124; www.prandah.com</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-19456</link>
		<dc:creator>New Instalation Kloxo guide &#124; www.prandah.com</dc:creator>
		<pubDate>Wed, 07 Dec 2011 09:41:24 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-19456</guid>
		<description>[...] that, you may want to install third-party firewall management scripts such as CSF (cache) or APF (cache) and its complements to detect and block threats like brute-force attacks and unauthorized [...]</description>
		<content:encoded><![CDATA[<p>[...] that, you may want to install third-party firewall management scripts such as CSF (cache) or APF (cache) and its complements to detect and block threats like brute-force attacks and unauthorized [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Real customer service is more than a catchy marketing phrase</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-19222</link>
		<dc:creator>Real customer service is more than a catchy marketing phrase</dc:creator>
		<pubDate>Fri, 02 Dec 2011 17:03:38 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-19222</guid>
		<description>[...] Most of our customers use the Advanced Policy Firewall by R-fx Networks.  [...]</description>
		<content:encoded><![CDATA[<p>[...] Most of our customers use the Advanced Policy Firewall by R-fx Networks.  [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Peter M. Abraham</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-18832</link>
		<dc:creator>Peter M. Abraham</dc:creator>
		<pubDate>Thu, 24 Nov 2011 14:30:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-18832</guid>
		<description>Good day, Ryan:

On some servers where their DNS is shaky at start up, APF basically locks up the machine because there appears to be no time out.

Can you please put in some logic that tests to see if DNS is working the way APF needs it to start, and then skip starting (sending an email out notifying it did not start)?

Thank you.</description>
		<content:encoded><![CDATA[<p>Good day, Ryan:</p>
<p>On some servers where their DNS is shaky at start up, APF basically locks up the machine because there appears to be no time out.</p>
<p>Can you please put in some logic that tests to see if DNS is working the way APF needs it to start, and then skip starting (sending an email out notifying it did not start)?</p>
<p>Thank you.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Locking Down Your Linux Server with APF + BFD &#124; Snipe.Net &#124; MKfmn &#124; Matthew M. Kaufman</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-18344</link>
		<dc:creator>Locking Down Your Linux Server with APF + BFD &#124; Snipe.Net &#124; MKfmn &#124; Matthew M. Kaufman</dc:creator>
		<pubDate>Sat, 19 Nov 2011 11:23:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-18344</guid>
		<description>[...] access and protect yourself from brute force attacks. Two of my favorite scripts to do this are Advanced Policy Firewall coupled with Brute Force Detection, both by R-FX [...]</description>
		<content:encoded><![CDATA[<p>[...] access and protect yourself from brute force attacks. Two of my favorite scripts to do this are Advanced Policy Firewall coupled with Brute Force Detection, both by R-FX [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Kloxo Installation Guide&#160;&#124;&#160;blog netforall</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-18164</link>
		<dc:creator>Kloxo Installation Guide&#160;&#124;&#160;blog netforall</dc:creator>
		<pubDate>Thu, 17 Nov 2011 13:33:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-18164</guid>
		<description>[...] For that, you may want to install third-party firewall management scripts such as CSF (cache) or APF (cache) and its complements to detect and block threats like brute-force attacks and unauthorized [...]</description>
		<content:encoded><![CDATA[<p>[...] For that, you may want to install third-party firewall management scripts such as CSF (cache) or APF (cache) and its complements to detect and block threats like brute-force attacks and unauthorized [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Securing cPanel After Install &#171; Recon Hosting Docs</title>
		<link>http://www.rfxn.com/projects/advanced-policy-firewall/#comment-17796</link>
		<dc:creator>Securing cPanel After Install &#171; Recon Hosting Docs</dc:creator>
		<pubDate>Sun, 13 Nov 2011 04:06:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.rfxn.com/?page_id=44#comment-17796</guid>
		<description>[...] firewall and bruteforce detection mechanism such as the free firewall [CSF]. Other options include [APF]+[BFD], or custom iptables [...]</description>
		<content:encoded><![CDATA[<p>[...] firewall and bruteforce detection mechanism such as the free firewall [CSF]. Other options include [APF]+[BFD], or custom iptables [...]</p>
]]></content:encoded>
	</item>
</channel>
</rss>

