{"id":18360,"date":"2026-09-29T21:06:26","date_gmt":"2026-09-29T18:06:26","guid":{"rendered":"https:\/\/www.hyyat.com\/knowledgebase\/open-port-csf-firewall-whm\/"},"modified":"2026-09-29T21:06:26","modified_gmt":"2026-09-29T18:06:26","password":"","slug":"open-port-csf-firewall-whm","status":"publish","type":"docs","link":"https:\/\/www.hyyat.com\/en\/knowledgebase\/open-port-csf-firewall-whm\/","title":{"rendered":"How to Open a Port in the CSF Firewall from WHM"},"content":{"rendered":"<div class=\"hy-tldr\" style=\"background:#f6f7fb;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:0 0 20px;line-height:1.8\"><strong>In short:<\/strong> To open a port in CSF: log in to WHM, go to Plugins, then ConfigServer Security &amp; Firewall, then Firewall Configuration. Add the port number to TCP_IN (incoming) and\/or TCP_OUT (outgoing), separated by commas, click Change, then click Restart csf+lfd.<\/div>\n<p>Sometimes a service on your server needs a specific port that the CSF firewall blocks by default. This guide shows how to allow it.<\/p>\n<h2>What is CSF?<\/h2>\n<p>Every Linux server needs a firewall that blocks suspicious activity and lets you block any IP address easily. One of the best free firewalls is <strong>ConfigServer Security &amp; Firewall (CSF)<\/strong>. It is recommended for servers running WHM\/cPanel, because it automatically blocks IP addresses that try to log in with wrong details too many times. Its login failure daemon is called lfd.<\/p>\n<h2>Steps<\/h2>\n<p><strong>1.<\/strong> Log in to WHM at <strong>https:\/\/your-server-ip:2087<\/strong> with your username and password.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/1_whm_firewall.png\" alt=\"Log in to WHM\" \/><\/p>\n<p><strong>2.<\/strong> Go to <strong>Plugins<\/strong> and click <strong>ConfigServer Security &amp; Firewall<\/strong>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/2_whm_firewall.png\" alt=\"ConfigServer Security and Firewall in WHM\" \/><\/p>\n<p><strong>3.<\/strong> Click <strong>Firewall Configuration<\/strong> and scroll to <strong>IPv4 Port Settings<\/strong>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/3_whm_firewall.png\" alt=\"CSF Firewall Configuration\" \/><\/p>\n<p><strong>4.<\/strong> Add the port to <strong>TCP_IN<\/strong> to allow incoming connections and to <strong>TCP_OUT<\/strong> to allow outgoing connections (use UDP_IN\/UDP_OUT for UDP services). Separate ports with commas.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/4_whm_firewall.png\" alt=\"TCP_IN and TCP_OUT ports in CSF\" \/><\/p>\n<p><strong>5.<\/strong> Save your changes by clicking <strong>Change<\/strong>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/5_whm_firewall.png\" alt=\"Save CSF changes\" \/><\/p>\n<p><strong>6.<\/strong> Restart the firewall by clicking <strong>Restart csf+lfd<\/strong>.<\/p>\n<p><img decoding=\"async\" src=\"https:\/\/www.hyyat.com\/zasogooh\/2019\/02\/6_whm_firewall.png\" alt=\"Restart csf and lfd\" \/><\/p>\n<p><strong>Tip:<\/strong> only open the ports you really need. Every open port is a possible way into your server.<\/p>\n<p class=\"hy-svc-link\" style=\"background:#fff5f7;border-left:4px solid #d83954;border-radius:10px;padding:14px 18px;margin:20px 0;line-height:1.8\"><strong>Related service:<\/strong> <a href=\"https:\/\/www.hyyat.com\/en\/server-management\/\">Hyyat Host server management<\/a> configures and secures your server firewall for you, with 24\/7 support.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In short: To open a port in CSF: log in to WHM, go to Plugins, then ConfigServer Security &amp; Firewall, then Firewall Configuration. Add the port number to TCP_IN (incoming) and\/or TCP_OUT (outgoing), separated by commas, click Change, then click Restart csf+lfd. Sometimes a service on your server needs a specific port that the CSF [&hellip;]<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","template":"","meta":{"inline_featured_image":false,"_templately_pack_id":"","_templately_imported_at":"","_templately_source":"","_templately_import_session_id":"","footnotes":""},"doc_category":[2734],"doc_tag":[],"class_list":["post-18360","docs","type-docs","status-publish","hentry","doc_category-whm-cpanel-control-panels"],"year_month":"2026-10","word_count":244,"total_views":"6","reactions":{"happy":"0","normal":"0","sad":"0"},"author_info":{"name":"ahmed fathy","author_nicename":"ahmed-fathy","author_url":"https:\/\/www.hyyat.com\/en\/author\/ahmed-fathy\/"},"doc_category_info":[{"term_name":"whm\/cpanel control panels","term_url":"https:\/\/www.hyyat.com\/en\/kb\/whm-cpanel-control-panels\/"}],"doc_tag_info":[],"knowledge_base_info":[],"knowledge_base_slug":[],"_links":{"self":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18360","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs"}],"about":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/types\/docs"}],"author":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/comments?post=18360"}],"version-history":[{"count":0,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/docs\/18360\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/media?parent=18360"}],"wp:term":[{"taxonomy":"doc_category","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_category?post=18360"},{"taxonomy":"doc_tag","embeddable":true,"href":"https:\/\/www.hyyat.com\/en\/wp-json\/wp\/v2\/doc_tag?post=18360"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}