Firewall & Security Hardening

how you can identify if CSF has blacklisted your IP and how to fix it - VPS

By the Domain India teamPublished 7 min read
Knowledge base article
Contents (8 sections)

ConfigServer Security & Firewall (CSF) is a firewall for Linux servers, and its companion daemon, LFD, watches the logs and blocks IP addresses that fail to log in too often. When LFD blocks your own IP, your server seems to vanish: SSH, the control panel, email and even the website time out, but only for you. This guide is for your own VPS or server, where you have root access and can remove the block yourself.

Key takeaways

If your server times out on your connection but works on mobile data, CSF has probably blocked your IP. Connect from another network, run csf -g YOUR_IP to see the block and its reason, then csf -dr YOUR_IP (permanent) or csf -tr YOUR_IP (temporary) to remove it. Fix the device with the wrong password first, or you will be blocked again. On Domain India shared hosting the firewall is ours: send your IP to support instead.

On shared hosting? This isn't your firewall

If your website is on Domain India cPanel, DirectAdmin or Webuzo hosting, you can't run these commands. Follow I can't reach my server: have I been blocked? and send your public IP to support.

1. Confirm it is a block, not an outage

TestPoints to an IP blockPoints to a server problem
Open the site on mobile data (Wi-Fi off)WorksFails too
SSH from another networkConnectsFails too
What the browser showsSpins, then times outAn error page such as 500 or 503
Who is affectedEveryone on your office or home connectionEveryone

A firewall block drops your packets, so you see a timeout rather than an error. If the server doesn't respond from anywhere, check your provider's console for the server's state instead.

2. Find your public IP address

From the blocked connection, search "what is my IP", or run:

bash
curl -4 ifconfig.me
curl -6 ifconfig.me

Note both addresses if you have IPv4 and IPv6. The address in your computer's network settings, such as 192.168.x.x, is private and won't appear in the firewall. Most offices share one public IP, so one device can block everyone.

3. Get back in

You need a way onto the server that isn't blocked:

  • Another network: mobile data or a hotspot usually has a different IP.
  • Your provider's console: a VPS normally has a browser console (VNC or similar) in the provider's panel, which bypasses the firewall.
  • A colleague's connection or a VPN, if your policy allows it.

Then become root with sudo -i or log in as root.

4. Check whether CSF blocked you, and why

bash
csf -g 203.0.113.25

Replace 203.0.113.25 with your IP. The output shows every rule that matches. Look for a line from csf.deny (a permanent block) or a temporary block, with a comment giving the reason and time, for example repeated SSH, FTP, IMAP or control panel login failures.

To see the log entries behind the block:

bash
grep 203.0.113.25 /var/log/lfd.log | tail -n 20

The reason names the service that failed, which tells you which device or app to fix.

5. Remove the block

  1. Fix the cause first.
    Correct the saved password in the mail app, FTP client or script that failed, or switch it off for now. If it keeps retrying, LFD blocks you again within minutes.
  2. Remove a permanent block.
    csf -dr 203.0.113.25
  3. Remove a temporary block.
    csf -tr 203.0.113.25
  4. Check it is gone.
    Run csf -g 203.0.113.25 again; no deny line should remain.
  5. Test from the blocked connection,
    then bring your devices back one at a time.

These commands take effect immediately; you don't need to restart CSF. Other useful commands:

bash
csf -t          # list all temporary blocks
csf -tf         # flush all temporary blocks
csf -r          # restart CSF after editing its config files

Avoid editing /etc/csf/csf.deny by hand while CSF is running when a command will do the job.

6. Also check the control panel's own protection

Some control panels keep their own brute-force list next to CSF. If you remove the CSF block and are blocked again straight away, check the panel too:

  • cPanel & WHM: cPHulk Brute Force Protection in WHM keeps its own blocked list. Clear your IP there as well.
  • DirectAdmin: the Brute Force Monitor keeps a record of failed logins. Clear your IP there as well, or the firewall may block it again.
  • Fail2ban or UFW: if the server runs these instead of, or as well as, CSF, use fail2ban-client set sshd unbanip YOUR_IP or ufw status numbered and ufw delete N.

7. Prevent the next block

Allow-list a fixed IP only
If your office has a static IP, csf -a YOUR_IP "office" adds it to csf.allow. Never allow-list home or mobile IPs; they change and are shared.
Use SSH keys
Key login ends password failures from typos and scripts. Then consider turning password login off.
Tune, don't disable
In /etc/csf/csf.conf, the LF_ settings control how many failures trigger a block per service. Raise a threshold a little rather than switching LFD off, then run csf -r.
Tidy saved passwords
After a password change, update it on every phone, laptop and app that uses the account.

csf.allow lets an IP through the firewall. csf.ignore tells LFD not to block an IP for login failures. Use them only for addresses you control.

CSF is no longer maintained by its original developer

ConfigServer stopped developing and supporting CSF in 2025. Existing installations keep working, but new security updates are not coming from the original vendor. For a new server, consider the firewall tools your distribution maintains, such as firewalld or nftables with Fail2ban, and check the status of any community-maintained fork before relying on it.

8. Where Domain India fits

A Domain India VPS is self-managed: you have full root access, and the firewall you install is yours to run, including unblocking your own IP. Prices on the card are live and exclude 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

If you would rather not manage a firewall at all, shared hosting keeps it in our hands; if you're blocked there, support removes the block for you.

How do I know CSF has blocked my IP?

Your server times out from your own connection but works from mobile data or another network. On the server, run csf -g followed by your IP; a deny entry confirms the block and shows the reason.

What is the command to unblock an IP in CSF?

Run csf -dr followed by the IP to remove a permanent block, or csf -tr followed by the IP to remove a temporary one. The change takes effect immediately without restarting CSF.

Why does CSF keep blocking my IP?

A device or script on your connection keeps failing to log in, usually an email app or FTP client with an old password. Check the reason in /var/log/lfd.log and fix the saved password before you unblock.

How do I get into my VPS if my IP is blocked?

Connect from a different network such as mobile data, or use your VPS provider's browser console, which is not affected by the server firewall.

Can I unblock my IP on Domain India shared hosting?

No. On Domain India cPanel, DirectAdmin and Webuzo hosting the firewall belongs to the server. Send your public IP address to support by live chat or ticket, and the team removes the block.

Should I whitelist my IP in CSF?

Only if it is a fixed IP that belongs to you, such as an office static IP. Home and mobile IPs change and are shared with other people.

Ready to secure your server further? Read the VPS firewall setup guide, or, if you're on shared hosting, open a ticket with your public IP.

Blocked on shared hosting?

Tell us your public IP address, your domain and which service stopped working, and support will check the server firewall.

Send us your IP

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app