# CSF DirectAdmin Install: Tune CSF/LFD Safely (Post-1.689)

Source: https://srvscripts.com/guides/csf-directadmin-install-tune/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

ConfigServer closed on 31 August 2025 and CSF 15.00 was its final release. DirectAdmin picked up the code and maintains its own fork, currently 15.05, distributed from `files.directadmin.com/services/csf-15.05.tar.gz` and developed in the open under the `poralix/da-csf` project. CustomBuild installs that fork, so on DirectAdmin you should not fetch CSF from any other source. The fork tracks bug fixes and log-format changes (OpenSSH 9.8 parsing, for instance) rather than adding features, and DirectAdmin’s 1.689 release changed a few defaults that the original never had.

In short: Run ./build set csf yes and ./build csf in /usr/local/directadmin/custombuild to install DirectAdmin’s 15.05 fork with the panel plugin.

**Short answer:** Run `./build set csf yes` and `./build csf` in `/usr/local/directadmin/custombuild` to install DirectAdmin’s 15.05 fork with the panel plugin. Then edit `/etc/csf/csf.conf`: set `TESTING = "0"`, list only the ports the server uses, enable `LF_DIRECTADMIN`, `LF_SSHD` and `LF_SMTPAUTH`, keep `MESSENGER = "0"` and no remote lists, allow your office and monitoring addresses with `csf -a`, and apply with `csf -ra`. On EL10 also set `LF_IPSET = "0"`.

## Installing through CustomBuild

Enable and build:

```
cd /usr/local/directadmin/custombuild
./build set csf yes
./build csf
```

This installs CSF and LFD, the DirectAdmin plugin that gives a firewall page under **Admin Level**, and the systemd units. On a fresh server the firewall starts in testing mode with a cron job that flushes the rules every five minutes, so nothing is enforced until you finish the configuration below. On EL9 and EL10 CSF drives nftables through the `iptables-nft` compatibility layer, which works, but on EL10 `ipset` is currently broken, so LFD blocklists that rely on it need `LF_IPSET = "0"` until that is resolved.

For Debian 13, the fork installs cleanly; for AlmaLinux 10 there were compile problems in December 2025 that have since been addressed in the fork, but if `./build csf` fails on a very new OS image, check the `da-csf` issue tracker before spending time on it.

## What DirectAdmin changed in 1.689

Two defaults were switched off because they generated noise on hosting servers: `LF_INTEGRITY = "0"` (binary integrity checking, which alerts on every package update) and `PT_LIMIT = "0"` (process tracking, which flags long-running customer PHP processes). At the same time PHP-FPM logs moved to the journal. If you want either check back, turn it on deliberately after the initial noise from updates has settled.

## The settings to tune

Edit `/etc/csf/csf.conf`. These are the values we set on every DirectAdmin node, in the order they matter:

```
TESTING = "0"
TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995,2222"
TCP_OUT = "20,21,22,25,53,80,110,113,443,587,993,995,2222"
UDP_IN = "20,21,53"
UDP_OUT = "20,21,53,113,123"
RESTRICT_SYSLOG = "3"
LF_SSHD = "5"
LF_SSHD_PERM = "1"
LF_DIRECTADMIN = "5"
LF_SMTPAUTH = "5"
LF_POP3D = "10"
LF_IMAPD = "10"
LF_MODSEC = "5"
CT_LIMIT = "300"
SYNFLOOD = "1"
DENY_IP_LIMIT = "500"
MESSENGER = "0"
```

Add the port the server uses for passive FTP if you run one, and the SSH port if it is not 22. `LF_DIRECTADMIN` is the panel login-failure trigger and reads `/var/log/directadmin/security.log`; leave it enabled. `MESSENGER` is discussed below. Country blocking with `CC_DENY` is effective on servers that serve a regional audience, but remember that it also blocks customers travelling abroad and the CAs’ validation servers, so if you use it, allow the ACME validation networks or wildcard-only the SMTP and IMAP ports.

Allow your own monitoring and management addresses so an operator typo never locks you out:

```
csf -a 203.0.113.10 "office"
csf -a 198.51.100.0/24 "monitoring"
```

Then restart and check for syntax errors:

```
csf -ra
csf -l | head -n 30
systemctl status lfd --no-pager
```

## The 2026 vulnerabilities and the fork

Three serious CSF vulnerabilities were disclosed in 2026: CVE-2026-65638 (remote code execution through the MESSENGER service when it is enabled together with a reCAPTCHA secret), CVE-2026-65639 (code execution via `URLGET` fetching remote allow and deny lists) and CVE-2026-67402 (the Messenger v3 HTTPS virtual host exposing `/usr/bin` as CGI). All were fixed in the cPanel fork’s 16.30 and 16.31 releases in August and September. The DirectAdmin fork is a separate line, so check the `da-csf` changelog for the equivalent fixes before assuming 15.05 is patched. The safe configuration regardless of version is the one above: `MESSENGER = "0"`, and no remote URLs in `csf.blocklists` or the allow/deny files that you do not control.

Confirm the installed version and that updates come from DirectAdmin’s channel:

```
csf -v
grep -E '^(DOWNLOADSERVER|AUTO_UPDATES)' /etc/csf/csf.conf
```

`AUTO_UPDATES` should be on and the download server should be the DirectAdmin one; a server upgraded from an older CSF may still point at the retired ConfigServer host and will simply never update.

## Common pitfall: LFD and the panel’s own traffic

LFD counts failed logins per IP, and a customer behind a corporate NAT with several employees mistyping the panel password will get the whole office blocked. Set `LF_TRIGGER_PERM` to a temporary block rather than permanent, keep `LF_DIRECTADMIN` at a reasonable count, and teach support staff to look in `/var/log/lfd.log` and use `csf -g <ip>` before assuming a customer’s connectivity problem is elsewhere.

## Verify

From an outside host, confirm only the intended ports answer:

```
nmap -Pn -p 1-65535 --open your.server.ip
```

Then deliberately fail SSH authentication six times from a test address and confirm it is blocked within a minute in `csf -g`. Finally, run the [server security audit](/scripts/server-security-audit/) script, which checks CSF’s testing flag, open ports and the messenger setting alongside the rest of the host’s hardening. The SSH-side settings that complement CSF are covered in [Hardening SSH on AlmaLinux 9](/guides/harden-ssh-almalinux-9/).

## CSF DirectAdmin install at a glance

**Official documentation:** [DirectAdmin documentation](https://docs.directadmin.com/), [Linux man pages](https://man7.org/linux/man-pages/).

**Related guides:** [Certificate not renewing on DirectAdmin: reading the Provisioning History page and lego output](https://srvscripts.com/guides/directadmin-certificate-not-renewing/) · [Migrating domains to DirectAdmin’s new ACME TLS system (1.706+) and running the migration task](https://srvscripts.com/guides/directadmin-acme-tls-migration-1-706/) · [Exim, Dovecot or DirectAdmin still serving the old certificate after renewal](https://srvscripts.com/guides/directadmin-old-certificate-exim-dovecot/).

## Frequently asked questions

### Does the DirectAdmin CSF fork include the fixes for the 2026 Messenger and URLGET CVEs?

The DirectAdmin fork is a separate line from the cPanel 16.x releases, so check the da-csf changelog for CVE-2026-65638, 65639 and 67402 before assuming; keeping MESSENGER off and remote lists disabled is safe on any version.

### How long does CSF stay in testing mode after CustomBuild installs it?

Until you set TESTING = “0” and restart; while testing is on, a cron job flushes the rules every five minutes, so nothing is enforced and a lockout cannot persist.

### Can I re-enable LF_INTEGRITY and PT_LIMIT that DirectAdmin turned off in 1.689?

Yes. Set them to non-zero values in csf.conf and run `csf -ra`; expect integrity alerts after every package update and process-tracking alerts for long-running customer PHP, which is why DirectAdmin disabled them by default.
