Emergency server help: get in touch

CSF DirectAdmin Install: Tune CSF/LFD Safely (Post-1.689)

How to install the DirectAdmin-maintained fork of ConfigServer Security & Firewall through CustomBuild, the defaults DirectAdmin changed in 1.689, the settings worth tuning on a hosting server, and the 2026 CSF vulnerabilities that affect the fork.

Published Updated 6 min read

ConfigServer closed on 31 August 2025 and CSF 15.00 was its final release. DirectAdmin picked up the code and maintains its own fork, currently 15.05, distributed from files.directadmin.com/services/csf-15.05.tar.gz and developed in the open under the poralix/da-csf project. CustomBuild installs that fork, so on DirectAdmin you should not fetch CSF from any other source. The fork tracks bug fixes and log-format changes (OpenSSH 9.8 parsing, for instance) rather than adding features, and DirectAdmin’s 1.689 release changed a few defaults that the original never had.

Applies to DirectAdmin 1.689 and later; DirectAdmin CSF fork 15.05 on EL9, EL10 and Debian 13

Short answer: Run ./build set csf yes and ./build csf in /usr/local/directadmin/custombuild to install DirectAdmin’s 15.05 fork with the panel plugin. Then edit /etc/csf/csf.conf: set TESTING = "0", list only the ports the server uses, enable LF_DIRECTADMIN, LF_SSHD and LF_SMTPAUTH, keep MESSENGER = "0" and no remote lists, allow your office and monitoring addresses with csf -a, and apply with csf -ra. On EL10 also set LF_IPSET = "0".

Installing through CustomBuild

Enable and build:

cd /usr/local/directadmin/custombuild
./build set csf yes
./build csf

This installs CSF and LFD, the DirectAdmin plugin that gives a firewall page under Admin Level, and the systemd units. On a fresh server the firewall starts in testing mode with a cron job that flushes the rules every five minutes, so nothing is enforced until you finish the configuration below. On EL9 and EL10 CSF drives nftables through the iptables-nft compatibility layer, which works, but on EL10 ipset is currently broken, so LFD blocklists that rely on it need LF_IPSET = "0" until that is resolved.

For Debian 13, the fork installs cleanly; for AlmaLinux 10 there were compile problems in December 2025 that have since been addressed in the fork, but if ./build csf fails on a very new OS image, check the da-csf issue tracker before spending time on it.

What DirectAdmin changed in 1.689

Two defaults were switched off because they generated noise on hosting servers: LF_INTEGRITY = "0" (binary integrity checking, which alerts on every package update) and PT_LIMIT = "0" (process tracking, which flags long-running customer PHP processes). At the same time PHP-FPM logs moved to the journal. If you want either check back, turn it on deliberately after the initial noise from updates has settled.

The settings to tune

Edit /etc/csf/csf.conf. These are the values we set on every DirectAdmin node, in the order they matter:

TESTING = "0"
TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995,2222"
TCP_OUT = "20,21,22,25,53,80,110,113,443,587,993,995,2222"
UDP_IN = "20,21,53"
UDP_OUT = "20,21,53,113,123"
RESTRICT_SYSLOG = "3"
LF_SSHD = "5"
LF_SSHD_PERM = "1"
LF_DIRECTADMIN = "5"
LF_SMTPAUTH = "5"
LF_POP3D = "10"
LF_IMAPD = "10"
LF_MODSEC = "5"
CT_LIMIT = "300"
SYNFLOOD = "1"
DENY_IP_LIMIT = "500"
MESSENGER = "0"

Add the port the server uses for passive FTP if you run one, and the SSH port if it is not 22. LF_DIRECTADMIN is the panel login-failure trigger and reads /var/log/directadmin/security.log; leave it enabled. MESSENGER is discussed below. Country blocking with CC_DENY is effective on servers that serve a regional audience, but remember that it also blocks customers travelling abroad and the CAs’ validation servers, so if you use it, allow the ACME validation networks or wildcard-only the SMTP and IMAP ports.

Allow your own monitoring and management addresses so an operator typo never locks you out:

csf -a 203.0.113.10 "office"
csf -a 198.51.100.0/24 "monitoring"

Then restart and check for syntax errors:

csf -ra
csf -l | head -n 30
systemctl status lfd --no-pager

The 2026 vulnerabilities and the fork

Three serious CSF vulnerabilities were disclosed in 2026: CVE-2026-65638 (remote code execution through the MESSENGER service when it is enabled together with a reCAPTCHA secret), CVE-2026-65639 (code execution via URLGET fetching remote allow and deny lists) and CVE-2026-67402 (the Messenger v3 HTTPS virtual host exposing /usr/bin as CGI). All were fixed in the cPanel fork’s 16.30 and 16.31 releases in August and September. The DirectAdmin fork is a separate line, so check the da-csf changelog for the equivalent fixes before assuming 15.05 is patched. The safe configuration regardless of version is the one above: MESSENGER = "0", and no remote URLs in csf.blocklists or the allow/deny files that you do not control.

Confirm the installed version and that updates come from DirectAdmin’s channel:

csf -v
grep -E '^(DOWNLOADSERVER|AUTO_UPDATES)' /etc/csf/csf.conf

AUTO_UPDATES should be on and the download server should be the DirectAdmin one; a server upgraded from an older CSF may still point at the retired ConfigServer host and will simply never update.

Common pitfall: LFD and the panel’s own traffic

LFD counts failed logins per IP, and a customer behind a corporate NAT with several employees mistyping the panel password will get the whole office blocked. Set LF_TRIGGER_PERM to a temporary block rather than permanent, keep LF_DIRECTADMIN at a reasonable count, and teach support staff to look in /var/log/lfd.log and use csf -g <ip> before assuming a customer’s connectivity problem is elsewhere.

Verify

From an outside host, confirm only the intended ports answer:

nmap -Pn -p 1-65535 --open your.server.ip

Then deliberately fail SSH authentication six times from a test address and confirm it is blocked within a minute in csf -g. Finally, run the server security audit script, which checks CSF’s testing flag, open ports and the messenger setting alongside the rest of the host’s hardening. The SSH-side settings that complement CSF are covered in Hardening SSH on AlmaLinux 9.

CSF DirectAdmin install at a glance

CSF DirectAdmin Install summary card: Run ./build set csf yes and ./build csf in /usr/local/directadmin/custombuild to install DirectAdmin's 15.05 fork with…
In short: Run ./build set csf yes and ./build csf in /usr/local/directadmin/custombuild to install DirectAdmin’s 15.05 fork with the panel plugin.

Official documentation: DirectAdmin documentation, Linux man pages.

Related guides: Certificate not renewing on DirectAdmin: reading the Provisioning History page and lego output · Migrating domains to DirectAdmin’s new ACME TLS system (1.706+) and running the migration task · Exim, Dovecot or DirectAdmin still serving the old certificate after renewal.

Frequently asked questions

Does the DirectAdmin CSF fork include the fixes for the 2026 Messenger and URLGET CVEs?

The DirectAdmin fork is a separate line from the cPanel 16.x releases, so check the da-csf changelog for CVE-2026-65638, 65639 and 67402 before assuming; keeping MESSENGER off and remote lists disabled is safe on any version.

How long does CSF stay in testing mode after CustomBuild installs it?

Until you set TESTING = “0” and restart; while testing is on, a cron job flushes the rules every five minutes, so nothing is enforced and a lockout cannot persist.

Can I re-enable LF_INTEGRITY and PT_LIMIT that DirectAdmin turned off in 1.689?

Yes. Set them to non-zero values in csf.conf and run csf -ra; expect integrity alerts after every package update and process-tracking alerts for long-running customer PHP, which is why DirectAdmin disabled them by default.

Maintenance record

This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.

Maintained by
srvScripts editorial team
Supported versions
DirectAdmin 1.689 and later; DirectAdmin CSF fork 15.05 on EL9, EL10 and Debian 13
Last full review
Next review

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.