---
title: How to Open a Port in the CSF Firewall from WHM
description: "**In short:** To open a port in CSF: log in to WHM, go to Plugins, then ConfigServer Security & Firewall, then Firewall Configuration. Add the port number to TCP_IN (incoming) and/or TCP_OUT (outgoing), separated by commas, click Change, then click…"
url: "https://www.hyyat.com/en/knowledgebase/open-port-csf-firewall-whm/"
updated: "2026-09-29"
category: Server management / whm/cpanel control panels
---

# How to Open a Port in the CSF Firewall from WHM

**In short:** To open a port in CSF: log in to WHM, go to Plugins, then ConfigServer Security & Firewall, then Firewall Configuration. Add the port number to TCP_IN (incoming) and/or TCP_OUT (outgoing), separated by commas, click Change, then click Restart csf+lfd.

Sometimes a service on your server needs a specific port that the CSF firewall blocks by default. This guide shows how to allow it.

## What is CSF?

Every Linux server needs a firewall that blocks suspicious activity and lets you block any IP address easily. One of the best free firewalls is **ConfigServer Security & Firewall (CSF)**. It is recommended for servers running WHM/cPanel, because it automatically blocks IP addresses that try to log in with wrong details too many times. Its login failure daemon is called lfd.

## Steps

**1.** Log in to WHM at **https://your-server-ip:2087** with your username and password.

![Log in to WHM](https://www.hyyat.com/wp-content/uploads/2019/02/1_whm_firewall.png)

**2.** Go to **Plugins** and click **ConfigServer Security & Firewall**.

![ConfigServer Security and Firewall in WHM](https://www.hyyat.com/wp-content/uploads/2019/02/2_whm_firewall.png)

**3.** Click **Firewall Configuration** and scroll to **IPv4 Port Settings**.

![CSF Firewall Configuration](https://www.hyyat.com/wp-content/uploads/2019/02/3_whm_firewall.png)

**4.** Add the port to **TCP_IN** to allow incoming connections and to **TCP_OUT** to allow outgoing connections (use UDP_IN/UDP_OUT for UDP services). Separate ports with commas.

![TCP_IN and TCP_OUT ports in CSF](https://www.hyyat.com/wp-content/uploads/2019/02/4_whm_firewall.png)

**5.** Save your changes by clicking **Change**.

![Save CSF changes](https://www.hyyat.com/wp-content/uploads/2019/02/5_whm_firewall.png)

**6.** Restart the firewall by clicking **Restart csf+lfd**.

![Restart csf and lfd](https://www.hyyat.com/wp-content/uploads/2019/02/6_whm_firewall.png)

**Tip:** only open the ports you really need. Every open port is a possible way into your server.

**Related service:** [Hyyat Host server management](https://www.hyyat.com/en/server-management/) configures and secures your server firewall for you, with 24/7 support.

 **Need this service from Hyyat Host?**Our team handles it for you, with support replying to tickets within 24 hours at most.[Server Management](https://www.hyyat.com/en/server-management/)[dedicated server](https://www.hyyat.com/en/dedicated-server/)
