Short answer: csf -a 203.0.113.10 "comment" allows an IP, csf -d 203.0.113.10 "comment" blocks it, and csf -dr 203.0.113.10 removes the block. csf -tr 203.0.113.10 clears a temporary LFD ban, and csf -g 203.0.113.10 shows every rule that matches the IP. Ports are set in TCP_IN/TCP_OUT/UDP_IN/UDP_OUT in /etc/csf/csf.conf, then csf -r. Use csf.allow to let an IP through the firewall and csf.ignore to stop LFD from banning it.
Applies to CSF v15 builds (cPanel and DirectAdmin forks); tested on CSF v15.12, DirectAdmin, AlmaLinux 9.8
We ran csf -h, csf -v, csf -g, csf -t and csf --lfd status on our DirectAdmin lab server (AlmaLinux 9.8, CSF v15.12, DirectAdmin build) on 6 October 2026. Our cPanel lab currently runs without CSF. Commands that add, remove or flush rules were checked against that server’s csf -h output, csf.conf comments and readme.txt. We did not run them, because our lab rules forbid firewall changes.
Table of Contents
First: which CSF are you running?
ConfigServer (Way to the Web Ltd) closed on 31 August 2025. CSF was released under GPLv3 and lives on as forks, so in 2026 “CSF” can mean different builds:
- cPanel servers: cPanel maintains a fork packaged as
cpanel-csf(yum install cpanel-csfon AlmaLinux/CloudLinux,apt install cpanel-csfon Ubuntu). According to cPanel’s announcement, servers on CSF 14.00 to 15.00 withAUTO_UPDATESenabled were moved to it automatically. The fork receives security and stability fixes only. cPanel still treats CSF as a third-party plugin. - DirectAdmin servers: DirectAdmin ships its own CSF build. On our lab,
csf -vprintscsf: v15.12 (DirectAdmin). - Other forks exist for other panels and plain servers. Our CSF fork 2026 comparison covers them, and migrating to the cPanel CSF fork covers the switch on cPanel.
csf -v # version and build
cat /etc/csf/version.txt # version only
All commands below come from the v15 command set and work the same on these builds. Before you script anything, run csf -h on your own server to confirm. Several 2026 CVEs affected older CSF builds, so check you are patched: see CSF CVE-2026-65638 patch guide.
CSF commands quick reference
| Task | Command | Notes |
|---|---|---|
| Allow an IP permanently | csf -a 203.0.113.10 "office" | Adds to /etc/csf/csf.allow |
| Remove an allowed IP | csf -ar 203.0.113.10 | Removes from csf.allow |
| Block an IP permanently | csf -d 203.0.113.10 "spam" | Adds to /etc/csf/csf.deny |
| Unblock a permanent block | csf -dr 203.0.113.10 | Removes from csf.deny |
| Unblock everything in csf.deny | csf -df | Removes every entry, so back up csf.deny first |
| Show temporary bans/allows | csf -t | IP, TTL and comment |
| Remove a temporary entry | csf -tr 203.0.113.10 | Ban or allow; -trd ban only, -tra allow only |
| Temporary ban | csf -td 203.0.113.10 1h -p 22 | TTL in seconds or with h/m/d suffix; port optional |
| Temporary allow | csf -ta 203.0.113.10 2h | Default direction inout |
| Flush all temporary entries | csf -tf | |
| Find an IP in the rules | csf -g 203.0.113.10 | Searches iptables, ip6tables and ipsets |
| List the IPv4 rules | csf -l | csf -l6 for IPv6 |
| Listening ports | csf -p | Ports with a process listening |
| Restart csf | csf -r | csf -ra restarts csf and then lfd |
| Disable / enable csf and lfd | csf -x / csf -e | |
| lfd daemon | csf --lfd status | stop, start, restart, status |
| Look up an IP’s country | csf -i 203.0.113.10 | Uses CC_LOOKUPS |
Allow, block and unblock IP addresses
csf -a 203.0.113.10 "Office static IP" # allow
csf -a 192.168.1.0/24 "Backup network" # CIDR works too
csf -d 203.0.113.10 "Brute force on WHM" # permanent block
csf -dr 203.0.113.10 # unblock (removes from csf.deny)
csf -g 203.0.113.10 # check: which rules match now?
Always add a comment. It is written next to the entry in csf.allow or csf.deny, and six months later it is the only record of why the IP is there.
Real output of csf -g for an address that is not in any rule (from our DirectAdmin lab):
Table Chain num pkts bytes target prot opt in out source destination
No matches found for 203.0.113.10 in iptables
IPSET: No matches found for 203.0.113.10
ip6tables:
Table Chain num pkts bytes target prot opt in out source destination
No matches found for 203.0.113.10 in ip6tables
csf -g is a text search. When we ran csf -g 22 on the lab, it matched port 22 rules and also rule numbers and allow-list IPs that contain “22”. Search for the full IP. To look for a port, use the full rule text instead, for example csf -l | grep "dpt:22 ".
csf.allow vs csf.ignore vs csf.deny
| File | What it does | Typical use |
|---|---|---|
/etc/csf/csf.allow | Allows the IP through the firewall. lfd can still ban it unless IGNORE_ALLOW is enabled. | Office IPs, monitoring, backup servers |
/etc/csf/csf.ignore | lfd ignores the IP in all its checks, so it is never auto-banned. It does not open any ports. | Your own admin IP, a NAT gateway shared by a whole office |
/etc/csf/csf.deny | Permanent block, kept across restarts. Limited by DENY_IP_LIMIT. | Known bad hosts |
The csf.allow header on our lab says it plainly: “IP addressess listed in this file will NOT be ignored by lfd, so they can still be blocked.” If your own IP keeps getting banned for failed logins, put it in csf.ignore and restart lfd (csf -ra), not only in csf.allow.
When csf.deny reaches DENY_IP_LIMIT entries (200 on our lab), CSF drops the oldest entries to make room. That is why an old block can quietly disappear. If you need thousands of permanent blocks, the csf.conf comments recommend the IPSET option.
Allow one port for one IP (advanced filters)
csf.allow and csf.deny accept port+IP filters in the format tcp/udp|in/out|s/d=port|s/d=ip. You need both a port and an IP. Examples in the readme style:
# MySQL from one application server only (add to /etc/csf/csf.allow)
tcp|in|d=3306|s=203.0.113.10
# SSH, HTTP and HTTPS from one IP (protocol defaults to tcp, direction to in)
d=22,80,443|s=203.0.113.10
Edit the file, then run csf -r. If 3306 is also listed in TCP_IN, it is open to everyone and the filter adds nothing. Remove it from TCP_IN first.
Temporary bans and LFD blocks
Most blocks on a busy server come from lfd (the login failure daemon), not from you. lfd adds temporary bans for failed SSH, FTP, mail and panel logins. csf -t lists them with their remaining time:
csf -t # list temporary entries
csf -tr 203.0.113.10 # remove the IP from temp bans and temp allows
csf -td 203.0.113.10 3600 -p 22 -d in # ban for 1 hour, port 22 only
csf -ta 203.0.113.10 2h # temporary allow (e.g. a contractor)
grep 203.0.113.10 /var/log/lfd.log # why lfd blocked it
On our lab, with nothing banned, csf -t printed csf: There are no temporary IP entries. The temporary lists live in /var/lib/csf/ (csf.tempban, csf.tempallow). Change them through csf -t* commands, not by editing those files.
Why does an IP come back as a permanent block? With LF_PERMBLOCK = "1", an IP that was temporarily blocked more than LF_PERMBLOCK_COUNT times within LF_PERMBLOCK_INTERVAL seconds is moved to csf.deny. Our lab uses a count of 4 and an interval of 86400. Look in csf.deny for those IPs (csf -dr), not in the temp list.
Per-service sensitivity is set by the LF_* triggers (for example LF_SSHD). With LF_TRIGGER = "0", each trigger value is the number of failures before a block. With LF_TRIGGER above 0, the triggers just switch on or off, and LF_TRIGGER becomes the total failure count across services.
Open or close ports
Ports are comma-separated lists in /etc/csf/csf.conf. Ranges use a colon. This is the real TCP_IN line from our DirectAdmin lab, which includes the passive FTP range 35000:35999 and the DirectAdmin port 2222:
TCP_IN = "35000:35999,20,21,22,25,53,853,80,110,143,443,465,587,993,995,2222"
Safe way to change ports:
- Back up the config with the built-in profile tool:
csf --profile backup "before-port-change". - Edit
TCP_IN,TCP_OUT,UDP_INorUDP_OUTin/etc/csf/csf.conf. - Apply:
csf -r(orcsf -rato restart lfd too). - Check from outside, and check with
csf -l | grep "dpt:8443 "that the rule exists. - If something broke:
csf --profile list, thencsf --profile restore <backup>andcsf -r.
If you are moving SSH to a new port, add the new port to TCP_IN and restart csf before you change sshd_config. Keep your current session open until a new login works. For VoIP servers, see our SIP ports firewall rules.
Restart, stop and disable CSF
csf -r # reload rules
csf -ra # restart csf, then lfd (after any config file change)
csf -q # quick restart via lfd
csf -f # flush/stop rules (lfd may restart csf)
csf -x # disable csf and lfd completely
csf -e # enable again
csf --lfd restart
csf -f and csf -x leave the server with no firewall. Use them only while you troubleshoot, and run csf -e as soon as you are done. Set TESTING = "1" on a new install: a cron job then clears the rules in case you lock yourself out, and lfd does not start until you set it back to 0.
Common problems
- Locked out after a change: log in through the provider’s console, run
csf -tr <your IP>orcsf -dr <your IP>, then add your IP tocsf.ignore. - An allowed IP still gets blocked: csf.allow does not stop lfd. Add the IP to csf.ignore, or enable
IGNORE_ALLOW(the csf.conf comments warn that an infected PC on an allowed IP could then attack unnoticed). - An unblocked IP is blocked again later: it is still failing logins (wrong saved password in a mail client), or LF_PERMBLOCK promoted it. Check
/var/log/lfd.log. - csf.conf changes have no effect: you edited the file but did not run
csf -ra. - ipset errors on AlmaLinux 10: see CSF on AlmaLinux 10: nftables and ipset.
Official documentation: cPanel: CSF fork announcement and install · DirectAdmin docs: CSF
Related: CSF Fork 2026: Which Reliable Replacement After ConfigServer? · Migrating a cPanel server to the cPanel CSF fork and verifying auto-updates · Hardening CSF safely: disabling Messenger, remote lists and other risky options · CSF CVE-2026-65638, 65639, 67402: Critical Patch Guide · AI Firewall Rule Builder for CSF, firewalld, nftables and UFW
See also: Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall · Open Port Checker: Test TCP Ports on Any Public Server · Imunify360 False Positives: Find the Rule ID and Fix It
See also: fail2ban vs CSF in 2026: Which Firewall for a Hosting Server?
Frequently asked questions
How do I unblock an IP in CSF?
Run csf -dr IP for a permanent block in csf.deny and csf -tr IP for a temporary lfd ban. If you are unsure which applies, run csf -g IP and csf -t first.
What is the difference between csf.allow and csf.ignore?
csf.allow lets an IP through the firewall, but lfd can still ban it. csf.ignore tells lfd never to ban the IP, but opens no ports. For your own admin IP you usually want both.
How do I open a port in CSF?
Add the port to TCP_IN or UDP_IN in /etc/csf/csf.conf and run csf -r. To open a port for a single IP only, use an advanced filter such as tcp|in|d=3306|s=203.0.113.10 in csf.allow.
Is CSF still maintained after ConfigServer shut down?
The original project ended on 31 August 2025. cPanel maintains a fork for cPanel servers (cpanel-csf), DirectAdmin ships its own build, and other community forks exist. Run csf -v to see which one you have.
How long does a CSF temporary ban last?
As long as the TTL set by the lfd trigger or by csf -td. csf -t shows the time left. If the IP is banned again often enough, LF_PERMBLOCK can turn it into a permanent block in csf.deny.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- CSF v15 builds (cPanel and DirectAdmin forks); tested on CSF v15.12, DirectAdmin, AlmaLinux 9.8
- Last full review
- Next review