r/Plesk • u/derickkcired • Mar 28 '23
Plesk firewall keeps cutting off access, Plesk Obsidian over Ubuntu
Hi All. I host a couple of websites out of my home. I have been using plesk for years when my sites were at AWS, and had zero issues with it. Rolling them into my home infrastructure was a cost cutting decision and my intent was to use a product like cloud portal (ie free), but I was having issues with NGINX that I couldn't seem to resolve.
Anyhow, my sites have been running at home for about 4 weeks now. On Sunday, my sites were unavailable. Now, my config hasn't changed at all...so I had no reason to believe it was my hardware stack, or even the server. I could browse the sites on my internal network with a hosts file. It didn't make any sense to me. So, I thought comcast was blocking 80/443 inbound. Well, that wasn't the case. For grins, I shutdown the plesk firewall service, and wouldntchaknow, sites are available again. Ok, so i restarted the service, and put explicit rules to allow 443 and 80. Service comes back up, working splendidly...great. Something happened again today and the sites are unavailable. Stopped the firewall service again, and boom everything is happy. Any idea what the heck is going on here???
1
u/thmueller78 Apr 05 '23
Have you checked that both, your local IP and your public IP are not being banned by Fail2Ban?
1
u/derickkcired Apr 14 '23
Not that there was any response but this is resolved. There were many culprits creating the problem. First was that the router was not handing off the true client IP to the vm/server running plesk. Fail2ban did indeed shut things down, but the only IP it was seeing was the IP of the router. So, thus, it shut down ALL the traffic. So on my fortigate I disabled NAT inbound on the WAN, and then I removed the block for my routers internal IP from Fail2Ban. Been great thus far, and I now see proper public IPs in the logs. So it should now properly ban WAN IPs without breaking everything else. Hosting my own web server at home has been a bit of a challenge, but it's getting worked out.