Emergency server help: get in touch

CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans

CSF commands for 2026: allow, deny and unblock IPs, temporary LFD bans, csf.allow vs csf.ignore, port lists and restarts, plus which CSF fork you are running.

Published Updated 10 min read

Short answer: csf -a 203.0.113.10 "comment" allows an IP, csf -d 203.0.113.10 "comment" blocks it, and csf -dr 203.0.113.10 removes the block. csf -tr 203.0.113.10 clears a temporary LFD ban, and csf -g 203.0.113.10 shows every rule that matches the IP. Ports are set in TCP_IN/TCP_OUT/UDP_IN/UDP_OUT in /etc/csf/csf.conf, then csf -r. Use csf.allow to let an IP through the firewall and csf.ignore to stop LFD from banning it.

Applies to CSF v15 builds (cPanel and DirectAdmin forks); tested on CSF v15.12, DirectAdmin, AlmaLinux 9.8

We ran csf -h, csf -v, csf -g, csf -t and csf --lfd status on our DirectAdmin lab server (AlmaLinux 9.8, CSF v15.12, DirectAdmin build) on 6 October 2026. Our cPanel lab currently runs without CSF. Commands that add, remove or flush rules were checked against that server’s csf -h output, csf.conf comments and readme.txt. We did not run them, because our lab rules forbid firewall changes.

First: which CSF are you running?

ConfigServer (Way to the Web Ltd) closed on 31 August 2025. CSF was released under GPLv3 and lives on as forks, so in 2026 “CSF” can mean different builds:

  • cPanel servers: cPanel maintains a fork packaged as cpanel-csf (yum install cpanel-csf on AlmaLinux/CloudLinux, apt install cpanel-csf on Ubuntu). According to cPanel’s announcement, servers on CSF 14.00 to 15.00 with AUTO_UPDATES enabled were moved to it automatically. The fork receives security and stability fixes only. cPanel still treats CSF as a third-party plugin.
  • DirectAdmin servers: DirectAdmin ships its own CSF build. On our lab, csf -v prints csf: v15.12 (DirectAdmin).
  • Other forks exist for other panels and plain servers. Our CSF fork 2026 comparison covers them, and migrating to the cPanel CSF fork covers the switch on cPanel.
csf -v                       # version and build
cat /etc/csf/version.txt     # version only

All commands below come from the v15 command set and work the same on these builds. Before you script anything, run csf -h on your own server to confirm. Several 2026 CVEs affected older CSF builds, so check you are patched: see CSF CVE-2026-65638 patch guide.

CSF commands quick reference

TaskCommandNotes
Allow an IP permanentlycsf -a 203.0.113.10 "office"Adds to /etc/csf/csf.allow
Remove an allowed IPcsf -ar 203.0.113.10Removes from csf.allow
Block an IP permanentlycsf -d 203.0.113.10 "spam"Adds to /etc/csf/csf.deny
Unblock a permanent blockcsf -dr 203.0.113.10Removes from csf.deny
Unblock everything in csf.denycsf -dfRemoves every entry, so back up csf.deny first
Show temporary bans/allowscsf -tIP, TTL and comment
Remove a temporary entrycsf -tr 203.0.113.10Ban or allow; -trd ban only, -tra allow only
Temporary bancsf -td 203.0.113.10 1h -p 22TTL in seconds or with h/m/d suffix; port optional
Temporary allowcsf -ta 203.0.113.10 2hDefault direction inout
Flush all temporary entriescsf -tf
Find an IP in the rulescsf -g 203.0.113.10Searches iptables, ip6tables and ipsets
List the IPv4 rulescsf -lcsf -l6 for IPv6
Listening portscsf -pPorts with a process listening
Restart csfcsf -rcsf -ra restarts csf and then lfd
Disable / enable csf and lfdcsf -x / csf -e
lfd daemoncsf --lfd statusstop, start, restart, status
Look up an IP’s countrycsf -i 203.0.113.10Uses CC_LOOKUPS

Allow, block and unblock IP addresses

csf -a 203.0.113.10 "Office static IP"         # allow
csf -a 192.168.1.0/24 "Backup network"         # CIDR works too
csf -d 203.0.113.10 "Brute force on WHM"       # permanent block
csf -dr 203.0.113.10                           # unblock (removes from csf.deny)
csf -g 203.0.113.10                            # check: which rules match now?

Always add a comment. It is written next to the entry in csf.allow or csf.deny, and six months later it is the only record of why the IP is there.

Real output of csf -g for an address that is not in any rule (from our DirectAdmin lab):

Table  Chain            num   pkts bytes target     prot opt in     out     source               destination
No matches found for 203.0.113.10 in iptables

IPSET: No matches found for 203.0.113.10

ip6tables:

Table  Chain            num   pkts bytes target     prot opt in     out     source               destination
No matches found for 203.0.113.10 in ip6tables

csf -g is a text search. When we ran csf -g 22 on the lab, it matched port 22 rules and also rule numbers and allow-list IPs that contain “22”. Search for the full IP. To look for a port, use the full rule text instead, for example csf -l | grep "dpt:22 ".

csf.allow vs csf.ignore vs csf.deny

FileWhat it doesTypical use
/etc/csf/csf.allowAllows the IP through the firewall. lfd can still ban it unless IGNORE_ALLOW is enabled.Office IPs, monitoring, backup servers
/etc/csf/csf.ignorelfd ignores the IP in all its checks, so it is never auto-banned. It does not open any ports.Your own admin IP, a NAT gateway shared by a whole office
/etc/csf/csf.denyPermanent block, kept across restarts. Limited by DENY_IP_LIMIT.Known bad hosts

The csf.allow header on our lab says it plainly: “IP addressess listed in this file will NOT be ignored by lfd, so they can still be blocked.” If your own IP keeps getting banned for failed logins, put it in csf.ignore and restart lfd (csf -ra), not only in csf.allow.

When csf.deny reaches DENY_IP_LIMIT entries (200 on our lab), CSF drops the oldest entries to make room. That is why an old block can quietly disappear. If you need thousands of permanent blocks, the csf.conf comments recommend the IPSET option.

Allow one port for one IP (advanced filters)

csf.allow and csf.deny accept port+IP filters in the format tcp/udp|in/out|s/d=port|s/d=ip. You need both a port and an IP. Examples in the readme style:

# MySQL from one application server only (add to /etc/csf/csf.allow)
tcp|in|d=3306|s=203.0.113.10

# SSH, HTTP and HTTPS from one IP (protocol defaults to tcp, direction to in)
d=22,80,443|s=203.0.113.10

Edit the file, then run csf -r. If 3306 is also listed in TCP_IN, it is open to everyone and the filter adds nothing. Remove it from TCP_IN first.

Temporary bans and LFD blocks

Most blocks on a busy server come from lfd (the login failure daemon), not from you. lfd adds temporary bans for failed SSH, FTP, mail and panel logins. csf -t lists them with their remaining time:

csf -t                                   # list temporary entries
csf -tr 203.0.113.10                     # remove the IP from temp bans and temp allows
csf -td 203.0.113.10 3600 -p 22 -d in    # ban for 1 hour, port 22 only
csf -ta 203.0.113.10 2h                  # temporary allow (e.g. a contractor)
grep 203.0.113.10 /var/log/lfd.log       # why lfd blocked it

On our lab, with nothing banned, csf -t printed csf: There are no temporary IP entries. The temporary lists live in /var/lib/csf/ (csf.tempban, csf.tempallow). Change them through csf -t* commands, not by editing those files.

Why does an IP come back as a permanent block? With LF_PERMBLOCK = "1", an IP that was temporarily blocked more than LF_PERMBLOCK_COUNT times within LF_PERMBLOCK_INTERVAL seconds is moved to csf.deny. Our lab uses a count of 4 and an interval of 86400. Look in csf.deny for those IPs (csf -dr), not in the temp list.

Per-service sensitivity is set by the LF_* triggers (for example LF_SSHD). With LF_TRIGGER = "0", each trigger value is the number of failures before a block. With LF_TRIGGER above 0, the triggers just switch on or off, and LF_TRIGGER becomes the total failure count across services.

Open or close ports

Ports are comma-separated lists in /etc/csf/csf.conf. Ranges use a colon. This is the real TCP_IN line from our DirectAdmin lab, which includes the passive FTP range 35000:35999 and the DirectAdmin port 2222:

TCP_IN = "35000:35999,20,21,22,25,53,853,80,110,143,443,465,587,993,995,2222"

Safe way to change ports:

  1. Back up the config with the built-in profile tool: csf --profile backup "before-port-change".
  2. Edit TCP_IN, TCP_OUT, UDP_IN or UDP_OUT in /etc/csf/csf.conf.
  3. Apply: csf -r (or csf -ra to restart lfd too).
  4. Check from outside, and check with csf -l | grep "dpt:8443 " that the rule exists.
  5. If something broke: csf --profile list, then csf --profile restore <backup> and csf -r.

If you are moving SSH to a new port, add the new port to TCP_IN and restart csf before you change sshd_config. Keep your current session open until a new login works. For VoIP servers, see our SIP ports firewall rules.

Restart, stop and disable CSF

csf -r            # reload rules
csf -ra           # restart csf, then lfd (after any config file change)
csf -q            # quick restart via lfd
csf -f            # flush/stop rules (lfd may restart csf)
csf -x            # disable csf and lfd completely
csf -e            # enable again
csf --lfd restart

csf -f and csf -x leave the server with no firewall. Use them only while you troubleshoot, and run csf -e as soon as you are done. Set TESTING = "1" on a new install: a cron job then clears the rules in case you lock yourself out, and lfd does not start until you set it back to 0.

Common problems

  • Locked out after a change: log in through the provider’s console, run csf -tr <your IP> or csf -dr <your IP>, then add your IP to csf.ignore.
  • An allowed IP still gets blocked: csf.allow does not stop lfd. Add the IP to csf.ignore, or enable IGNORE_ALLOW (the csf.conf comments warn that an infected PC on an allowed IP could then attack unnoticed).
  • An unblocked IP is blocked again later: it is still failing logins (wrong saved password in a mail client), or LF_PERMBLOCK promoted it. Check /var/log/lfd.log.
  • csf.conf changes have no effect: you edited the file but did not run csf -ra.
  • ipset errors on AlmaLinux 10: see CSF on AlmaLinux 10: nftables and ipset.

Official documentation: cPanel: CSF fork announcement and install · DirectAdmin docs: CSF

Related: CSF Fork 2026: Which Reliable Replacement After ConfigServer? · Migrating a cPanel server to the cPanel CSF fork and verifying auto-updates · Hardening CSF safely: disabling Messenger, remote lists and other risky options · CSF CVE-2026-65638, 65639, 67402: Critical Patch Guide · AI Firewall Rule Builder for CSF, firewalld, nftables and UFW

See also: Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall · Open Port Checker: Test TCP Ports on Any Public Server · Imunify360 False Positives: Find the Rule ID and Fix It

See also: fail2ban vs CSF in 2026: Which Firewall for a Hosting Server?

Frequently asked questions

How do I unblock an IP in CSF?

Run csf -dr IP for a permanent block in csf.deny and csf -tr IP for a temporary lfd ban. If you are unsure which applies, run csf -g IP and csf -t first.

What is the difference between csf.allow and csf.ignore?

csf.allow lets an IP through the firewall, but lfd can still ban it. csf.ignore tells lfd never to ban the IP, but opens no ports. For your own admin IP you usually want both.

How do I open a port in CSF?

Add the port to TCP_IN or UDP_IN in /etc/csf/csf.conf and run csf -r. To open a port for a single IP only, use an advanced filter such as tcp|in|d=3306|s=203.0.113.10 in csf.allow.

Is CSF still maintained after ConfigServer shut down?

The original project ended on 31 August 2025. cPanel maintains a fork for cPanel servers (cpanel-csf), DirectAdmin ships its own build, and other community forks exist. Run csf -v to see which one you have.

How long does a CSF temporary ban last?

As long as the TTL set by the lfd trigger or by csf -td. csf -t shows the time left. If the IP is banned again often enough, LF_PERMBLOCK can turn it into a permanent block in csf.deny.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
CSF v15 builds (cPanel and DirectAdmin forks); tested on CSF v15.12, DirectAdmin, AlmaLinux 9.8
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.