Firewall & Security Hardening

Installing and Optimizing CSF: A Comprehensive Guide

By the Domain India teamPublished 10 min read
Knowledge base article
Contents (10 sections)

ConfigServer Security & Firewall (CSF) is a firewall manager and login-failure daemon for Linux servers, long popular on servers running cPanel or DirectAdmin. This guide explains how to install it on a server you manage, the first settings to get right, and which options are worth tuning. It also covers what changed in 2025, because that should shape whether you install CSF at all on a new server.

Key takeaways

CSF is for your own VPS or server; on Domain India shared hosting the firewall is run by us and you can't change it. The company that developed CSF stopped work on it in 2025, so on a new server first decide whether firewalld, ufw or nftables with Fail2ban would serve you better. If you do install CSF, get it from a source that is still maintained, keep TESTING = "1" until SSH and your sites work, open ports for IPv4 and IPv6, and tune the login-failure limits before anything else.

This applies to your own VPS or server, not shared hosting

On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server firewall is managed by us for every account and customers can't change it. If you think your IP address has been blocked there, see I can't reach my server: have I been blocked?

1. What CSF does

CSF has two parts that work together:

csf
Builds the server's packet-filter rules from simple settings: which TCP and UDP ports are open inbound and outbound, which IPs are always allowed or always blocked, and connection limits.
lfd
The login failure daemon. It reads log files, counts failed logins to SSH, FTP, mail and control panels, and blocks IPs that fail too often. It can also email you alerts.

2. CSF's status in 2026

Way to the Web, the company behind ConfigServer and CSF, stopped developing CSF in 2025. The code was released as open source, and continued versions are distributed by others, but support for each operating system and control panel now depends on which version you use. When we checked on 24 September 2026, the original ConfigServer download site did not respond, so the wget install commands in older guides, including earlier versions of this one, no longer work.

Check the source before you install

Only install CSF from a source that is still maintained and that states support for your operating system and panel. Read its release notes, and check that its update command works. A firewall that no longer receives fixes is a liability on a new server.

3. CSF or the built-in firewall?

Your serverSensible choiceWhy
cPanel server you run yourselfCSF from a maintained source, or cPanel's own supported optionPanel integration and login-failure detection for every cPanel service
DirectAdmin serverCheck your CSF version supports DirectAdmin, otherwise firewalld plus DirectAdmin's brute-force monitorSupport differs between CSF versions
AlmaLinux or Rocky Linux without a panelfirewalld with Fail2banBoth are in the distribution's repositories and get security updates
Ubuntu or Debian without a panelufw with Fail2banSame reason; ufw is the standard front end there

For the built-in tools, follow Modern firewall management with nftables or the firewall guide. The rest of this article assumes you have chosen CSF.

4. Before you install

  • Use a supported operating system. CentOS 7 and 8 are end of life. Use AlmaLinux or Rocky Linux 8 or 9, or a current Ubuntu or Debian LTS release.
  • Install the Perl modules CSF needs. On AlmaLinux or Rocky Linux: dnf install perl-libwww-perl perl-LWP-Protocol-https perl-Time-HiRes. On Ubuntu or Debian: apt install libwww-perl liblwp-protocol-https-perl.
  • Run one firewall manager only. CSF, firewalld and ufw each expect to own the rules. Before you enable CSF, stop the other with systemctl disable --now firewalld or ufw disable.
  • Have a way back in. Find your provider's web console before you start. It works even when the firewall blocks SSH.

5. Install and run the self-test

The installer is a shell script inside the CSF archive. With the archive from your chosen source downloaded to /usr/src:

bash
cd /usr/src
tar -xzf csf.tgz
cd csf
sh install.sh

# check that the kernel and iptables support everything CSF uses
perl /usr/local/csf/bin/csftest.pl

Every line of csftest.pl should end in OK. On AlmaLinux and Rocky Linux 8 and later, the iptables command writes nftables rules behind the scenes, and CSF works through it unchanged; see managing CSF rules with nftables.

6. First configuration, safely

All main settings live in /etc/csf/csf.conf. Change them in this order:

  1. Keep testing mode on.
    TESTING = "1" makes CSF clear its rules every few minutes, so a mistake can't lock you out for long. It is on after a fresh install.
  2. Allow your own IP.
    Run csf -a 203.0.113.10 "my office" with your real address. It goes into csf.allow.
  3. Open only the ports you use.
    Edit TCP_IN, TCP_OUT, UDP_IN and UDP_OUT, and repeat them in TCP6_IN and the other IPv6 lines. Make sure your SSH port is in both.
  4. Set the alert address.
    Put your email in LF_ALERT_TO so lfd can tell you about blocks and suspicious activity.
  5. Apply and test from a second session.
    Run csf -ra, open a new SSH session and load your websites, keeping the first session open.
  6. Turn testing mode off.
    When everything works, set TESTING = "0" and run csf -ra again.

Keep your own extra rules in /etc/csf/csfpre.sh or /etc/csf/csfpost.sh. CSF rebuilds its rules on every restart, so rules added any other way disappear.

7. Optimising CSF: the settings that matter

Login failures (lfd). These give the most protection for the least risk. Each service has a limit and an optional block time:

ini
LF_SSHD = "5"
LF_SSHD_PERM = "3600"
LF_FTPD = "10"
LF_SMTPAUTH = "10"
LF_POP3D = "10"
LF_IMAPD = "10"
LF_TRIGGER = "0"

A _PERM value of 1 blocks permanently; a larger number is a block time in seconds. Temporary blocks are kinder to users who mistype a password. Leave LF_TRIGGER at 0, or one shared count replaces all the per-service limits.

Connection limits. CT_LIMIT, CONNLIMIT and PORTFLOOD slow down connection floods from a few IPs. Start with generous values and tighten slowly, because many real visitors can share one IP address. Safe starting values and the limits of what CSF can stop are in mitigating DDoS attacks using CSF. Leave SYNFLOOD off unless you are under a SYN flood.

Blocklists. /etc/csf/csf.blocklists contains commented-out examples of public IP blocklists. Enable only lists whose terms allow your use, and turn on LF_IPSET = "1" so large lists don't slow the firewall down.

Country rules. CC_DENY and CC_ALLOW need a GeoIP data source, chosen with CC_SRC; the MaxMind option needs a free licence key. Blocking whole countries also blocks your own customers and staff when they travel, so use it sparingly.

File and process alerts. LF_DIRWATCH is an interval in seconds for checking temporary folders for suspicious files, not a list of folders. To be alerted when specific files change, list them in LF_DIRWATCH_FILE. Process tracking (PT_USERMEM, PT_USERTIME) warns about processes that use too much memory or run too long.

8. Everyday commands and logs

bash
csf -a 203.0.113.10 "office"   # always allow an IP
csf -d 198.51.100.7 "abuse"    # block an IP permanently
csf -dr 198.51.100.7           # remove a permanent block
csf -td 198.51.100.7 3600      # block for one hour
csf -tr 198.51.100.7           # remove a temporary block
csf -g 198.51.100.7            # which rule matches this IP?
csf -ra                        # restart csf and lfd after a config change

Blocks and their reasons are written to /var/log/lfd.log; read it after every change. If you lock yourself out, use your provider's console and run csf -x to disable CSF, fix the setting, then csf -e to enable it again.

Before a big change, back up the folder with cp -a /etc/csf /root/csf-backup-$(date +%F). If your version's updates have stopped, plan a move to a maintained firewall.

9. Running this on Domain India

On Domain India shared hosting, the firewall is already managed for every account on the server. Measured on 20 September 2026, our cPanel and DirectAdmin servers run CSF alongside Imunify360, and the cPanel servers also have Imunify360's denial-of-service protection switched on. There is nothing for you to install. If you are blocked, follow how to diagnose and resolve CSF IP blocks.

A Domain India VPS is self-managed with full root access, so you choose and run the firewall: CSF from a maintained source, firewalld, ufw or nftables. cPanel is not offered on a VPS. The card shows the Domain India list price on 19 September 2026, excluding 18% GST.

VPS Starter
₹552.65/mo + GST
  • 1 vCPU
  • 2 GB DDR4 RAM
  • 64 GB NVMe SSD Storage
  • 2 TB Monthly Bandwidth
See plan details

Frequently asked questions

Is CSF still maintained in 2026?

Way to the Web, the company behind ConfigServer and CSF, stopped developing CSF in 2025 and released the code as open source. Continued versions are distributed by others. Before installing, check that the version you use is maintained and supports your operating system and control panel.

Can I still install CSF with the old wget command from configserver.com?

No. When checked on 24 September 2026, the original ConfigServer download site did not respond. Install CSF only from a source that is still maintained, or use firewalld, ufw or nftables with Fail2ban instead.

Can I install CSF with dnf or apt?

No. CSF is not in the standard AlmaLinux, Rocky Linux, Ubuntu or Debian repositories. It is installed with the install.sh script inside its archive.

Should I run CSF together with firewalld or ufw?

No. Each expects to manage the whole ruleset, and one will overwrite the other after a restart. Disable firewalld or ufw before you enable CSF.

How do I stop CSF locking me out while I set it up?

Keep TESTING set to 1, which clears the rules every few minutes, allow your own IP with csf -a, and make sure your SSH port is in TCP_IN and TCP6_IN. Test from a second SSH session before you set TESTING to 0.

Can I install or change CSF on Domain India shared hosting?

No. The firewall on Domain India shared hosting is managed by Domain India for every account on the server. CSF settings apply only to a VPS or server where you have root access.

Ready to run your own firewall? Compare VPS plans, read the VPS security checklist, or open a support ticket with your public IP address if you are blocked from a Domain India server.

A server where the firewall is yours

Self-managed KVM VPS with full root access and your choice of Linux, so you can run CSF, firewalld or nftables as you prefer.

See VPS plans

Ready when you are

Get VPS from ₹552.65/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Install and Optimize CSF Firewall (2026) | Domain India