
Every Linux server needs a firewall that blocks suspicious activity and lets you block any IP address easily. For servers running cPanel/WHM, the most popular choice is ConfigServer Security & Firewall (CSF). It is designed to block IP addresses that try to log in with wrong details again and again.
Main features #
- Login failure daemon (lfd): watches failed logins (SSH, FTP, email, cPanel) and blocks any IP that goes over the allowed number of attempts.
- Process tracking: watches for suspicious processes and newly opened ports, and alerts you or blocks them.
- Directory watching: watches sensitive folders for new or changed scripts, to catch malicious files early.
- Alerts: emails you reports, such as new blocks or new open ports.
- Port flood protection: limits the number of connections from one IP in a period, which helps against flood attacks.
- Port knocking: keeps ports hidden until a secret sequence of connection attempts opens them.
- Connection limits: limits connections per port or per IP.
- WHM integration: manage CSF from a graphical page in WHM.
- Allow and deny lists: allow-listed IPs skip the filters; deny-listed IPs are always blocked. CSF can also download block lists from several sources.
Installation and updates #
ConfigServer, the company that developed CSF, closed on 31 August 2025, and the old download link (download.configserver.com) no longer works. cPanel now provides and maintains CSF with security updates for cPanel & WHM servers.
To check your version, connect over SSH (see how to connect to your server over SSH) and run csf -v. If you see (cPanel) next to the version number, your copy comes from cPanel (the cpanel-csf package) and is updated with your system updates.
For useful commands, see important CSF commands over SSH. To install CSF on a new server or tune its settings, open a support ticket and our server management team will handle it.
Related service: Hyyat Host server management installs, configures and monitors your server firewall, with 24/7 support.