Emergency server help: get in touch

Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall

Run Imunify360 as the only firewall: back up and migrate CSF, disable it, recreate ports, DoS and SMTP blocking, and handle Security Advisor warnings.

Published 7 min read

Short answer: Imunify360 can be the only firewall on a cPanel or DirectAdmin server. While CSF is running, Imunify360 switches off its own Blocked Ports, DoS Protection and SMTP Traffic Manager; once CSF is gone those features take over. Back up your CSF lists, run Imunify360’s migrate_csf tool, disable CSF with csf -x and systemctl disable csf lfd, then set port rules and SMTP blocking in Imunify360. Expect a false “MySQL listening on all interfaces” warning in WHM Security Advisor.

Commands checked against the official Imunify360 documentation and cPanel knowledge base (linked below) on 6 October 2026; not yet run on our lab servers (our cPanel lab runs ImunifyAV, not Imunify360).

What changes when CSF is removed

Imunify360 and CSF are compatible, and both cPanel and CloudLinux say so. When Imunify360 detects CSF it hands three jobs to CSF and turns its own versions off:

FeatureWith CSF runningAfter CSF is removed
Open/closed portsCSF TCP_IN/TCP_OUT in csf.confImunify360 Blocked Ports (FIREWALL section)
Connection-flood (DoS) blockingCSF/LFD settingsImunify360 DoS Protection (DOS section)
Outgoing SMTP restrictionCSF SMTP_BLOCKImunify360 SMTP Traffic Manager (SMTP_BLOCKING section)
Allow/deny listscsf.allow, csf.deny, csf.ignoreImunify360 White List and Black List
Login brute forceLFD (plus cPHulk)Imunify360 (cPanel staff note it does the job of cPHulk)

Two details catch people out. First, CSF’s allow, deny and ignore lists are not imported automatically while both run; Imunify360 simply avoids blocking addresses in CSF’s allow and ignore lists. Second, Imunify360’s port blocking starts in ALLOW mode, where everything is open except what you list. CSF setups are usually the opposite (only listed ports open), so check the mode after the switch.

Back up CSF before you change anything

mkdir -p /root/csf-backup-$(date +%F)
cp -a /etc/csf/csf.conf /etc/csf/csf.allow /etc/csf/csf.deny /etc/csf/csf.ignore \
      /root/csf-backup-$(date +%F)/
grep -E "^(TCP_IN|TCP_OUT|UDP_IN|UDP_OUT|TCP6_IN|SMTP_BLOCK|SMTP_ALLOWUSER)" /etc/csf/csf.conf

Keep that grep output: it is your list of ports and SMTP rules to recreate. Then make sure you cannot lock yourself out. Add your office or VPN address (198.51.100.25 here) to the Imunify360 White List first:

imunify360-agent ip-list local add --purpose white 198.51.100.25 --comment "admin office"
imunify360-agent ip-list local list --purpose white --by-ip 198.51.100.25

Run the migrate_csf tool, then disable CSF

Imunify360 includes a migration tool. The documented commands are:

cd /opt/imunify360/venv/share/imunify360/scripts/migrate_csf
./main.py
less /var/log/imunify360/migrate_csf.log

Imunify360’s documentation does not list exactly which CSF settings the tool converts, so read its log and compare the result with your backup. Check at least the white list, the black list and the ports:

imunify360-agent ip-list local list --purpose white
imunify360-agent ip-list local list --purpose drop
imunify360-agent blocked-port list

When the lists look right, disable CSF so Imunify360’s firewall takes over. These are the commands Imunify360 documents:

csf -x
systemctl disable csf
systemctl disable lfd

Do this from a console or a session you know is whitelisted, and have provider console access ready. Removing the CSF package itself can wait a week; disabled CSF is easy to bring back with csf -e if something goes wrong.

Recreate port rules, DoS and SMTP blocking

Imunify360’s settings live in /etc/sysconfig/imunify360/imunify360.config, and its documentation says changes there apply automatically without a restart. You can also change them with imunify360-agent config update. Check the current values first:

imunify360-agent config show

Ports

In the FIREWALL section, port_blocking_mode is ALLOW (default: everything open except listed ports) or DENY (everything closed except listed ports). The allowed ports are set per direction and protocol: TCP_IN_IPv4, TCP_OUT_IPv4, UDP_IN_IPv4, UDP_OUT_IPv4 and the matching _IPv6 keys. To match a CSF-style “only these ports” policy:

  1. Copy your CSF TCP_IN/UDP_IN lists into the matching Imunify360 keys (in the Imunify360 settings UI, or in the config file using the same format config show prints).
  2. Check that SSH, the panel ports, mail ports and anything custom (monitoring agents, backups) are in the list.
  3. Only then switch port_blocking_mode to DENY:
imunify360-agent config update '{"FIREWALL": {"port_blocking_mode": "DENY"}}' 

For one-off closures in ALLOW mode, block a single port and allow exceptions per IP:

imunify360-agent blocked-port add 3306:tcp --comment "no public MySQL"
imunify360-agent blocked-port-ip add 3306:tcp --ips 192.0.2.50 --comment "app server"

DoS protection

The DOS section is enabled by default with interval 30 seconds and default_limit 250 connections from one IP to a local port (minimum 100). port_limits sets other thresholds per port. Raise limits for ports that legitimately get many connections from one address, such as a proxy or a CDN that does not pass client IPs.

Outgoing SMTP

CSF’s SMTP_BLOCK has a counterpart in the SMTP_BLOCKING section, which is off by default. Its defaults: ports 25, 587 and 465, allow_groups = mail, allow_users empty, allow_local and redirect off. If you used SMTP_BLOCK to stop scripts from sending mail directly, turn it on:

imunify360-agent config update '{"SMTP_BLOCKING": {"enable": true}}' 

Add any users you allowed in CSF’s SMTP_ALLOWUSER to allow_users. On cPanel you can use WHM’s own SMTP Restrictions instead, but not both.

WHM Security Advisor warnings after CSF is gone

Security Advisor was built with CSF in mind and does not always read Imunify360’s firewall state. Known cases from cPanel’s community and case tracker:

  • MySQL listening on all interfaces: after removing CSF, Security Advisor warns that MariaDB/MySQL is exposed even though Imunify360 blocks port 3306. In September 2025 cPanel staff confirmed it as a false positive and linked it to case CPANEL-48877. The suggested workaround, bind-address = 127.0.0.1, only fits servers where no customer needs remote database access.
  • “No brute force protection”: an older false positive while Imunify360 was active (CPANEL-40545), marked resolved in cPanel 112. If you see it on a current version, check that Imunify360 is licensed and running.

Before you dismiss a warning, prove the port is closed from outside, for example from another server:

nc -vz -w 3 203.0.113.10 3306

Check that it worked

systemctl is-active imunify360 csf lfd      # expect: active, inactive, inactive
imunify360-agent rstatus
imunify360-agent ip-list local list --purpose white
imunify360-agent blocked-port list
  • SSH, panel, web and mail ports answer from outside; closed ports (3306, internal services) do not.
  • A test IP added with --purpose drop is blocked, and removing it unblocks.
  • If SMTP blocking is on, a PHP script that connects directly to an outside port 25 fails, while mail through Exim still works.
  • Security Advisor shows only the known false positives above.

Common problems

  • Locked out after switching to DENY: the SSH or panel port was missing from TCP_IN_IPv4. Use the provider console, add the port, and confirm your IP is on the White List.
  • Blocked Ports page still greyed out: CSF is still running or enabled. Check systemctl is-active csf lfd.
  • Monitoring alerts stop: outgoing ports for monitoring or backup agents were open in CSF’s TCP_OUT but not in Imunify360. Add them.
  • Mail from a script stopped: SMTP blocking is on and the script’s user is not in allow_users.

Official documentation: Imunify360: CSF integration · Imunify360: Config file description · Imunify360: Command-line interface · cPanel: Are Imunify360 and CSF compatible?

Related: CSF Fork 2026: Which Reliable Replacement After ConfigServer? · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · Imunify360 Whitelist IP and Countries from the CLI: Commands · Replace CSF with firewalld and fail2ban: Secure Step-by-Step · Imunify360 review: worth it on a shared cPanel server?

See also: CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans · Open Port Checker: Test TCP Ports on Any Public Server · Imunify360 False Positives: Find the Rule ID and Fix It

Frequently asked questions

Can Imunify360 replace CSF completely?

Yes. Imunify360 has its own firewall, port blocking, DoS protection and SMTP traffic manager. Those features turn on when CSF is not running.

Does Imunify360 import csf.allow and csf.deny?

Not automatically while CSF runs. Use the migrate_csf tool before disabling CSF, then check the White and Black Lists.

Which ports does Imunify360 block by default?

Port blocking starts in ALLOW mode, so everything is open except ports you add. Switch to DENY mode only after listing every port you need.

Why does Security Advisor say MySQL is exposed after removing CSF?

cPanel confirmed this as a false positive (CPANEL-48877): Security Advisor does not read Imunify360’s rules. Test the port from outside to be sure.

Do I need cPHulk if I run Imunify360?

cPanel staff have said Imunify360 does what cPHulk does and both do not need to be enabled.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.