SSH & Terminal Access

Investigating IP Block Issues in DirectAdmin Hosting with Root Access

By the Domain India teamPublished 5 min read
Knowledge base article
Contents (4 sections)

This guide is for administrators of their own DirectAdmin VPS or server with root access. When a client, a developer or your own office can't reach a site on that server, the block usually comes from one of three places: the CSF firewall and its login daemon LFD, DirectAdmin's Brute Force Monitor, or ModSecurity. The checks below tell you which one, in a few minutes.

Key takeaways

If the whole server times out for one IP but works from mobile data, it is a firewall block: run csf -g IP and read /var/log/lfd.log. If the site loads but one page returns 403, it is usually ModSecurity: search /var/log/httpd/modsec_audit.log for the IP. Fix the cause, then remove the block or add a narrow rule exception. On Domain India shared hosting you have no root access; send your public IP to support instead.

For the full guides, see the canonical articles

1. Which kind of block is it?

Symptom from the affected IPLikely sourceCheck
Everything times out: site, webmail, FTP, SSH, panelCSF or LFD firewall blockcsf -g IP, then /var/log/lfd.log
The panel login keeps failing or re-blocks soon after an unblockDirectAdmin Brute Force MonitorThe Brute Force Monitor page in DirectAdmin as admin
Site loads, but one page or form returns 403ModSecurity rule/var/log/httpd/modsec_audit.log

2. The commands, in order

Replace 203.0.113.25 with the affected public IP. Connect from another network, or through your provider's console, if your own IP is the one blocked.

bash
# 1. Is it blocked by the firewall, and why?
csf -g 203.0.113.25
grep 203.0.113.25 /var/log/lfd.log | tail -n 20

# 2. Which service kept failing? (RHEL-based systems such as AlmaLinux)
grep 203.0.113.25 /var/log/secure | tail -n 20
grep 203.0.113.25 /var/log/maillog | grep -i "auth failed\|failed" | tail -n 20

# 3. Is ModSecurity refusing requests from it?
grep -n 203.0.113.25 /var/log/httpd/modsec_audit.log | tail -n 20
grep ModSecurity /var/log/httpd/error_log | grep 203.0.113.25 | tail -n 20

The LFD line names the service and the number of failures. The ModSecurity entry names the rule ID and the reason, which you need before you change anything.

Annotated example LFD log line showing the failing service, the blocked IP, the number of failures and that CSF blocked the IP
Reading an LFD line: which service failed, and how often

3. Remove the block the right way

  1. Fix the cause first.
    Update the old password saved in the mail app or FTP client, or stop the script that keeps failing. Otherwise LFD blocks the IP again within minutes.
  2. Remove the firewall block.
    csf -dr 203.0.113.25 removes a permanent block and csf -tr 203.0.113.25 a temporary one. Both take effect immediately.
  3. Clear the Brute Force Monitor entry
    for the IP in DirectAdmin too, or it can trigger a fresh block.
  4. For a ModSecurity false positive,
    add the smallest exception for that rule ID and URL, in DirectAdmin's custom configuration folder rather than the files CustomBuild regenerates. Then run apachectl configtest && systemctl reload httpd. Don't switch ModSecurity off.
  5. Allow-list only fixed IPs.
    csf -a IP "office" suits a static office IP you control, never a home or mobile IP.
ConfigServer stopped developing CSF in 2025

Existing CSF installations keep working. For a new server, consider firewalld or nftables with Fail2ban instead.

4. On Domain India shared hosting

On Domain India cPanel, DirectAdmin and Webuzo shared hosting the server and its firewall are ours, so there is no root access and no self-service unblock. Fix the device with the wrong password, then send support your public IP, your domain and the service that stopped working. For the customer-side walkthrough, see I can't reach my server: have I been blocked?

How do I check if CSF has blocked an IP on my DirectAdmin server?

As root, run csf -g followed by the IP. It shows any deny entry and its reason. The matching lines in /var/log/lfd.log name the service that kept failing.

How do I unblock an IP in CSF?

Run csf -dr followed by the IP to remove a permanent block, or csf -tr followed by the IP to remove a temporary one. Fix the failing login first, or the IP is blocked again.

Where is the ModSecurity log on DirectAdmin?

By default DirectAdmin's CustomBuild writes the ModSecurity audit log to /var/log/httpd/modsec_audit.log, with one-line summaries in /var/log/httpd/error_log.

Can I unblock my own IP on Domain India shared hosting?

No. On shared hosting the firewall belongs to the server. Send your public IP, domain and the failing service to support by live chat or ticket.

Ready to get unblocked? On your own server, work through the checks above. On Domain India shared hosting, open a ticket or use the public ticket form from mobile data. Live chat is available 24/7, and tickets get a first response within 15 minutes.

Blocked from your shared hosting?

Tell us your public IP address, your domain and which service stopped working, and support will check the server firewall.

Send us your IP

Ready when you are

Get DirectAdmin hosting from ₹100/mo + GST

See plans

Was this article helpful?

Your answer helps us decide what to improve next.

Still need help? Open a support ticket and our team will reply.

Prefer an app? Add this site to your home screen.Get the app
Find and Fix IP Blocks on a DirectAdmin Server (Root)