csf_ip_reason
Check why an IP is blocked by CSF/LFD, returning the firewall log reason such as failed SSH login attempts.
Instructions
Why CSF/LFD listed this IP (list + LFD comment). Safe to show an operator.
Parses csf -g via the plugin. Typical comment:
lfd: (sshd) Failed SSH login … 8 in the last 3600 secs.
Pair with bfm_ip_reason or use ip_block_reason for both + a customer text.
Args: ip: IPv4 or IPv6.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| ip | Yes |
Output Schema
| Name | Required | Description | Default |
|---|---|---|---|
| result | Yes |