ConfigServer Security & Firewall (CSF) was written for iptables, but on CentOS 8 and its successors, AlmaLinux and Rocky Linux 8 and 9, the kernel firewall is nftables. This guide explains how CSF works on those systems, how to manage its rules without breaking anything, and what to know about CSF's future before you rely on it on a new server.
On RHEL-based systems from version 8, the iptables command is a compatibility layer that writes nftables rules, so CSF keeps working unchanged. Manage everything through CSF (/etc/csf/csf.conf, csf.allow, csf.deny and the csf command) and only look at the result with nft list ruleset; never edit those tables by hand. Run one firewall manager at a time, so disable firewalld if you use CSF. CentOS 8 is end of life and CSF's original vendor has closed, so plan new servers on AlmaLinux or Rocky Linux and consider firewalld or plain nftables.
On Domain India cPanel, DirectAdmin and Webuzo shared hosting, the server firewall is managed by us and customers can't change it. If you think your IP is blocked there, see I can't reach my server: have I been blocked?
1. What changed from iptables to nftables
nftables replaced iptables as the Linux packet-filtering framework. On RHEL 8 and later (AlmaLinux, Rocky Linux, and the old CentOS 8), the iptables package is iptables-nft: it accepts the familiar iptables syntax and turns each rule into nftables rules behind the scenes. The older "iptables-legacy" backend is not shipped on these systems.
For CSF this is good news. CSF issues iptables commands, the compatibility layer translates them, and the firewall behaves as before. You do not need to rewrite anything.
For the nftables side of the picture (tables, sets, firewalld), read Modern firewall management with nftables on RHEL-based systems.
2. One firewall manager at a time
CSF, firewalld and a hand-written nftables service each expect to own the ruleset. If two run together, one replaces the other's rules after a reload or reboot, and you end up with ports open or closed that you didn't intend.
If you use CSF, turn firewalld off:
systemctl disable --now firewalld
systemctl status firewalld # should say inactive (dead)Docker also inserts its own rules. If the server runs containers, test their networking after every CSF restart.
3. Where CSF keeps its settings
| File | What it controls |
|---|---|
/etc/csf/csf.conf | Main settings: open ports (TCP_IN, TCP_OUT, TCP6_IN, UDP_IN), testing mode, login-failure limits |
/etc/csf/csf.allow | IPs and ranges always allowed |
/etc/csf/csf.deny | IPs and ranges permanently blocked |
/etc/csf/csf.ignore | IPs that the login-failure daemon (lfd) should never block |
/etc/csf/csfpre.sh, /etc/csf/csfpost.sh | Your own extra iptables commands, run before or after CSF's rules |
Keep any custom rules in csfpre.sh or csfpost.sh, never in nftables directly. CSF flushes and rebuilds its rules on every restart, so anything added elsewhere disappears.
Remember IPv6. A port opened in TCP_IN but not in TCP6_IN is still closed to visitors who connect over IPv6.
4. Everyday CSF commands
csf -a 203.0.113.10 "office" # allow an IP (adds it to csf.allow)
csf -d 198.51.100.7 "abuse" # block an IP (adds it to csf.deny)
csf -dr 198.51.100.7 # remove a permanent block
csf -td 198.51.100.7 3600 # block for one hour only
csf -tr 198.51.100.7 # remove a temporary block
csf -g 203.0.113.10 # search the live rules for an IP or port
csf -r # reload the firewall rules
csf -ra # restart the firewall and lfdAfter editing csf.conf, restart with csf -ra so lfd also picks up the change.
5. Change rules safely on a remote server
A wrong setting can cut off your SSH session. CSF has a built-in safety net called testing mode.
- Check the requirements.Run
perl /usr/local/csf/bin/csftest.pl. Every test should report OK. - Keep testing mode on while you set up.In
csf.conf,TESTING = "1"makes a cron job clear the rules every few minutes, so a mistake can't lock you out for long. - Make sure SSH is open.Your SSH port must be in
TCP_IN(andTCP6_INif you use IPv6). Add your own IP tocsf.allowtoo. - Restart and test from a second session.Run
csf -ra, open a new SSH session and load your websites, keeping the first session open. - Switch testing mode off.When everything works, set
TESTING = "0"and runcsf -raagain.
If you do lose access, use your provider's console, which is not affected by the firewall, and run csf -x to disable CSF while you fix the setting. Turn it back on with csf -e.
6. Checking what CSF applied in nftables
You can look at the translated rules at any time:
nft list ruleset | lessYou will see tables such as ip filter and ip6 filter with chains CSF created (for example LOCALINPUT and DENYIN), and possibly a comment like:
# Warning: table ip filter is managed by iptables-nft, do not touch!That warning means exactly what it says. Read these tables, but change them only through CSF. csf -l lists the same rules in iptables format, which is often easier to read.
7. Before you choose CSF for a new server
CentOS 8 reached end of life at the end of 2021, so move any remaining CentOS 8 server to AlmaLinux or Rocky Linux. Way to the Web, the company that made CSF, closed in August 2025 and no longer develops it. Community-maintained copies exist, but before installing CSF on a new server, confirm that the version you use is still receiving fixes.
If you don't need CSF's control-panel integration, a supported alternative is firewalld (the default on AlmaLinux and Rocky Linux) or a plain nftables ruleset, with Fail2ban for login-failure blocking. Both are covered in the nftables guide linked above, and UFW users can follow setting up a firewall on your VPS.
8. Running this on Domain India
A Domain India VPS is self-managed with full root access, so you choose and run the firewall yourself: CSF, firewalld, nftables or UFW. You can pick AlmaLinux or Rocky Linux when you order, and cPanel is not offered on a VPS. The card shows the live list price, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
For hardening beyond the firewall, see the VPS security checklist and the SSH security hardening checklist.
Does CSF work on AlmaLinux and Rocky Linux with nftables?
Yes. On RHEL-based systems from version 8, the iptables command is iptables-nft, which translates CSF's iptables rules into nftables. CSF runs without changes; manage it through its own files and commands.
Can I go back to iptables-legacy on CentOS 8 or AlmaLinux 8?
No. RHEL-based systems from version 8 ship only the nftables-based iptables. This does not affect CSF, which works through the compatibility layer.
Should I run CSF and firewalld together?
No. Both expect to own the firewall ruleset and one will overwrite the other. Disable firewalld with systemctl disable --now firewalld before you use CSF.
Why did my custom nftables rules disappear after csf -r?
CSF flushes and rebuilds its rules whenever it restarts. Put custom rules in /etc/csf/csfpre.sh or /etc/csf/csfpost.sh so CSF adds them every time.
How do I unblock an IP in CSF?
Run csf -dr followed by the IP for a permanent block, or csf -tr followed by the IP for a temporary one. Use csf -g with the IP to confirm no rule still matches it.
Is CSF still maintained?
Way to the Web, the company that developed CSF, closed in August 2025. Community-maintained copies exist; check that yours still receives fixes, or consider firewalld or nftables with Fail2ban on new servers.
Can I use CSF on Domain India shared hosting?
No. On shared hosting the server firewall is managed by Domain India and customers can't change it. CSF applies to your own VPS or server.
Ready to run your own firewall? Compare VPS plans, or if you're on shared hosting and blocked, open a ticket with your public IP address.
Self-managed KVM VPS with full root access and your choice of Linux, so you can run CSF, firewalld or nftables as you prefer.
See VPS plans