Emergency server help: get in touch

fail2ban vs CSF in 2026: Which Firewall for a Hosting Server?

fail2ban vs CSF for hosting servers in 2026: CSF fork status, features, nftables and AlmaLinux 10, resource use, cPanel/DirectAdmin/Plesk support and which to pick.

Published 9 min read

Short answer: CSF is a complete firewall (it opens and closes ports) plus a login-failure daemon (lfd) with process tracking and cPanel/DirectAdmin screens; fail2ban only reads logs and bans IPs, so it needs a firewall such as firewalld or nftables under it. On cPanel and DirectAdmin, CSF is still the easier fit in 2026 through the panel-maintained forks (cPanel’s cpanel-csf and DirectAdmin’s own build). On Plesk and on servers without a panel, use fail2ban with firewalld or nftables. Do not run both as separate firewalls on one server.

We ran the version and resource checks on this page on our lab servers on 7 October 2026: CSF v15.12 (DirectAdmin build) on AlmaLinux 9.8 with DirectAdmin 1.712, and fail2ban 1.0.2 on Debian 12 with FreePBX. Feature claims are checked against the CSF readme shipped with that build, the fail2ban source code and the vendor documentation linked below.

What CSF and fail2ban are in 2026

CSF: firewall plus lfd, now maintained as forks

ConfigServer Security & Firewall (CSF) writes the server’s packet-filter rules itself (allowed ports, allow and deny lists, flood limits) and runs lfd, a daemon that watches logs and processes and blocks IPs through CSF. Its original developer, Way to the Web Ltd (ConfigServer), closed on 31 August 2025 and released CSF under the GPLv3. cPanel’s support article says cPanel provides its own fork from 25 February 2026, installed as cpanel-csf, and that the fork gets critical security and stability fixes only, with no new features. DirectAdmin ships its own build: on our DirectAdmin lab, csf -v prints csf: v15.12 (DirectAdmin), and its changelog shows recent fixes such as a CVE patch in 15.12 and updated Dovecot and OpenSSH log patterns.

Other community forks exist for servers without these panels. Our CSF fork 2026 comparison covers them; the short version is to run the fork your panel vendor ships.

fail2ban: a log-based ban daemon

fail2ban is a Python daemon that tails log files (or the systemd journal), matches lines against filters, and when an IP fails too often within a time window it runs a ban action against a firewall. It does not manage ports or default policy; that stays with firewalld, nftables, iptables or another firewall. It is actively developed: the upstream repository has a 1.1.1 release tag and commits from September 2026, and EPEL packages 1.1.0 for EL9 and EL10.

Feature comparison

The CSF column describes the cPanel and DirectAdmin forks, which share the same configuration options. The fail2ban column describes upstream fail2ban with its bundled filters and actions.

FeatureCSF + lfdfail2ban
Port control (open/close ports, default deny)Yes: TCP_IN, TCP_OUT, IPv6 in csf.confNo; use firewalld or nftables for this
Login failure detectionBuilt in for SSH, FTP, SMTP AUTH, POP3, IMAP, panel logins, ModSecurity, .htaccess and more (LF_* options)Yes, through filters: sshd, dovecot, exim, postfix, pure-ftpd, proftpd, roundcube-auth, directadmin, mysqld-auth and many more; custom filters are regular expressions
Repeat offendersPermanent block after repeated temp blocks (LF_PERMBLOCK)recidive jail
Process trackingYes: user process count and memory limits (PT_USERPROC, PT_USERMEM) with alerts or killsNo
Directory and file watchingYes: LF_DIRWATCH for suspicious files in /tmp and similarNo
Connection and flood limitsYes: CONNLIMIT, PORTFLOOD, SYNFLOOD, CT_LIMITNo (it reacts to log lines, not connection counts)
Country blockingYes: CC_DENY, CC_ALLOWNo
Outbound SMTP restrictionYes: SMTP_BLOCKNo
Panel UIWHM, DirectAdmin and Webmin screens; InterWorx and CWP integrations listed in the readmeNo CSF-style UI; Plesk has its own fail2ban screen
Firewall backendWrites iptables rules; on AlmaLinux 9 these go through the iptables-nft layer (our lab: iptables v1.8.10 (nf_tables)), with ipset for large listsNative actions for nftables (nftables-multiport, nftables-allports), firewalld (firewallcmd-rich-rules, firewallcmd-ipset), iptables, and even CSF (csf)
Configuration styleOne large csf.conf plus allow/deny/ignore filesJails in jail.local / jail.d/, filters and actions as separate files
MaintenancePanel forks: fixes only (cPanel) or panel-driven (DirectAdmin)Active upstream project

nftables and AlmaLinux 10

This is the main long-term difference. Red Hat marked iptables-nft and ipset as deprecated in RHEL 9, and the RHEL 10 release notes say ipset is unmaintained and planned for removal in a future major release, recommending nftables sets instead. CSF still drives iptables commands, so it depends on that compatibility layer; before you deploy it on AlmaLinux 10, test your exact build (see CSF on AlmaLinux 10: nftables and ipset problems). fail2ban already talks to nftables and firewalld natively, so it does not have this dependency.

Resource use

Neither tool is heavy. A snapshot from our labs on 7 October 2026 (resident memory from ps):

ServerProcessMemory (RSS)Notes
DirectAdmin 1.712, AlmaLinux 9.8, 3 domainslfd - sleeping (CSF v15.12)about 35 MBDefault DirectAdmin CSF config: SSH, FTP, mail and panel login tracking, process tracking, LF_DIRWATCH = 300
FreePBX 17, Debian 12fail2ban-server 1.0.2about 33 MB8 jails, backend = auto

One server each is not a benchmark, but the point holds: memory is similar. CPU is where they differ under load. lfd’s cost grows with the extra checks you enable (process tracking, directory watching, connection tracking), and fail2ban’s grows with log volume and the number of regular expressions per line. On a busy mail server, keep fail2ban on the systemd journal or small dedicated logs, and on CSF turn off checks you do not use. To check your own server:

ps -eo pid,rss,etime,args | grep -E 'lfd|fail2ban-server' | grep -v grep
fail2ban-client status
csf -v

Panel compatibility: cPanel, DirectAdmin, Plesk

PanelCSFfail2ban
cPanel & WHMSupported fork cpanel-csf (yum install cpanel-csf or apt install cpanel-csf); WHM plugin; security and stability fixes onlyInstallable; cPanel’s install article notes that cPHulk does a similar job. No WHM screen
DirectAdminDirectAdmin’s own build via CustomBuild (csf=yes in options.conf on our lab); plugin in the DirectAdmin UIWorks; upstream ships a directadmin filter for panel logins
PleskNot listed in the CSF readme’s panel integrationsBuilt in as “IP Address Banning (Fail2Ban)” in Tools & Settings, with 13 preconfigured jails (Plesk docs)
No panelGeneric install of a community forkDistribution packages; pair with firewalld or nftables

Watch the EPEL package on cPanel and DirectAdmin. On EL9, the fail2ban meta-package from EPEL pulls in fail2ban-firewalld, which requires firewalld and sets banaction = firewallcmd-rich-rules. Running firewalld next to CSF gives you two firewalls fighting over the same rules. If you want fail2ban on a CSF server, install fail2ban-server only and use the csf action (next section).

Imunify360 is a third option on cPanel and DirectAdmin: it can replace CSF as the firewall and handles brute-force blocking itself (see Imunify360 without CSF).

Can you run fail2ban and CSF together?

Yes, if fail2ban only feeds CSF instead of writing its own rules. fail2ban ships an action, action.d/csf.conf, that bans with csf --deny <ip> and unbans with csf --denyrm <ip>. Its own header warns that CSF has been seen removing bans created by other iptables-based actions, and says not to mix CSF with other iptables actions. So set it for every jail:

# /etc/fail2ban/jail.local
[DEFAULT]
banaction = csf
banaction_allports = csf

[wordpress-login]
enabled  = true
filter   = wordpress-login
logpath  = /var/log/apache2/domlogs/*.log
maxretry = 10
findtime = 10m
bantime  = 1h

The wordpress-login filter is an example name: fail2ban does not ship one, so you write the filter yourself (our fail2ban regex generator can draft it from real log lines). Check the log path for your panel and web server. This pattern is useful when you want a ban rule CSF’s lfd does not have, while keeping CSF as the only firewall.

Which one to use: recommendation per scenario

ScenarioRecommendationWhy
cPanel shared hostingCSF (cpanel-csf) plus cPHulk, or Imunify360 instead of CSFWHM integration, process tracking and per-service login blocking out of the box; cPanel maintains the fork
DirectAdminDirectAdmin’s CSF buildInstalled and updated through CustomBuild with DirectAdmin-specific log patterns
PleskPlesk’s built-in fail2banAlready integrated with Plesk’s logs and UI; CSF does not list Plesk support
VPS without a panel (web, API, small mail)firewalld or nftables + fail2banNative nftables support, active upstream, small and easy to audit
New AlmaLinux 10 serverfirewalld + fail2ban, unless your panel ships and supports CSF on EL10Avoids the deprecated iptables-nft and ipset path
VoIP/Asterisk serverfail2ban with Asterisk jails behind firewalld or nftablesAsterisk security logs map well to fail2ban filters (see fail2ban for Asterisk and FreePBX)

If you are moving away from CSF, follow Replace CSF with firewalld and fail2ban; if you are staying on cPanel, migrating to the cPanel CSF fork covers the switch. Port lists and rules for either side can be drafted with our firewall rule builder.

Official documentation: cPanel: CSF fork announcement · fail2ban on GitHub · Plesk: Fail2Ban protection · RHEL 10: deprecated features

Related: CSF Fork 2026: Which Reliable Replacement After ConfigServer? · Replace CSF with firewalld and fail2ban: Secure Step-by-Step · CSF AlmaLinux 10: nftables and ipset Problems Fixed · AI fail2ban Regex Generator: Filters and Jails from Log Lines · Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall

See also: CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans · Replace CSF with firewalld and fail2ban: Secure Step-by-Step · Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall

Frequently asked questions

Is CSF still maintained in 2026?

The original ConfigServer project ended on 31 August 2025 and was released under the GPLv3. cPanel maintains a fixes-only fork called cpanel-csf, DirectAdmin maintains its own build, and other community forks exist. Run csf -v to see which one you have.

Is fail2ban a firewall?

Not on its own. fail2ban reads logs and bans IPs through a firewall backend such as nftables, firewalld or iptables. Port rules and default policy still come from that firewall.

Which uses fewer resources, CSF or fail2ban?

Memory is similar: about 35 MB for lfd and 33 MB for fail2ban-server on our labs. CPU depends on configuration, such as how many lfd checks are enabled or how much log data fail2ban parses.

Can I use fail2ban on a cPanel server?

Yes. Install fail2ban-server rather than the full EPEL meta-package if CSF is the firewall, and use the csf ban action so CSF stays in charge of the rules. cPanel also has cPHulk for login protection.

Does CSF support nftables?

CSF uses iptables commands, which on AlmaLinux 9 run on nftables through the iptables-nft layer. It has no native nftables backend, and Red Hat has deprecated iptables-nft and ipset, so test carefully on AlmaLinux 10.

Does Plesk use CSF or fail2ban?

Plesk includes fail2ban as its “IP Address Banning (Fail2Ban)” component with preconfigured jails. The CSF readme does not list Plesk among its supported panels.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.