# Imunify360 Without CSF: Remove CSF and Use Imunify as the Firewall

Source: https://srvscripts.com/guides/imunify360-without-csf/
Updated: 2026-10-06
Publisher: srvScripts (https://srvscripts.com/)

**Short answer:** Imunify360 can be the only firewall on a cPanel or DirectAdmin server. While CSF is running, Imunify360 switches off its own Blocked Ports, DoS Protection and SMTP Traffic Manager; once CSF is gone those features take over. Back up your CSF lists, run Imunify360’s `migrate_csf` tool, disable CSF with `csf -x` and `systemctl disable csf lfd`, then set port rules and SMTP blocking in Imunify360. Expect a false “MySQL listening on all interfaces” warning in WHM Security Advisor.

Commands checked against the official Imunify360 documentation and cPanel knowledge base (linked below) on 6 October 2026; not yet run on our lab servers (our cPanel lab runs ImunifyAV, not Imunify360).

## What changes when CSF is removed

Imunify360 and CSF are compatible, and both cPanel and CloudLinux say so. When Imunify360 detects CSF it hands three jobs to CSF and turns its own versions off:

| Feature | With CSF running | After CSF is removed |
| --- | --- | --- |
| Open/closed ports | CSF TCP_IN/TCP_OUT in csf.conf | Imunify360 Blocked Ports (FIREWALL section) |
| Connection-flood (DoS) blocking | CSF/LFD settings | Imunify360 DoS Protection (DOS section) |
| Outgoing SMTP restriction | CSF SMTP_BLOCK | Imunify360 SMTP Traffic Manager (SMTP_BLOCKING section) |
| Allow/deny lists | csf.allow, csf.deny, csf.ignore | Imunify360 White List and Black List |
| Login brute force | LFD (plus cPHulk) | Imunify360 (cPanel staff note it does the job of cPHulk) |

Two details catch people out. First, CSF’s allow, deny and ignore lists are not imported automatically while both run; Imunify360 simply avoids blocking addresses in CSF’s allow and ignore lists. Second, Imunify360’s port blocking starts in `ALLOW` mode, where everything is open except what you list. CSF setups are usually the opposite (only listed ports open), so check the mode after the switch.

## Back up CSF before you change anything

```
mkdir -p /root/csf-backup-$(date +%F)
cp -a /etc/csf/csf.conf /etc/csf/csf.allow /etc/csf/csf.deny /etc/csf/csf.ignore \
      /root/csf-backup-$(date +%F)/
grep -E "^(TCP_IN|TCP_OUT|UDP_IN|UDP_OUT|TCP6_IN|SMTP_BLOCK|SMTP_ALLOWUSER)" /etc/csf/csf.conf
```

Keep that grep output: it is your list of ports and SMTP rules to recreate. Then make sure you cannot lock yourself out. Add your office or VPN address (198.51.100.25 here) to the Imunify360 White List first:

```
imunify360-agent ip-list local add --purpose white 198.51.100.25 --comment "admin office"
imunify360-agent ip-list local list --purpose white --by-ip 198.51.100.25
```

## Run the migrate_csf tool, then disable CSF

Imunify360 includes a migration tool. The documented commands are:

```
cd /opt/imunify360/venv/share/imunify360/scripts/migrate_csf
./main.py
less /var/log/imunify360/migrate_csf.log
```

Imunify360’s documentation does not list exactly which CSF settings the tool converts, so read its log and compare the result with your backup. Check at least the white list, the black list and the ports:

```
imunify360-agent ip-list local list --purpose white
imunify360-agent ip-list local list --purpose drop
imunify360-agent blocked-port list
```

When the lists look right, disable CSF so Imunify360’s firewall takes over. These are the commands Imunify360 documents:

```
csf -x
systemctl disable csf
systemctl disable lfd
```

Do this from a console or a session you know is whitelisted, and have provider console access ready. Removing the CSF package itself can wait a week; disabled CSF is easy to bring back with `csf -e` if something goes wrong.

## Recreate port rules, DoS and SMTP blocking

Imunify360’s settings live in `/etc/sysconfig/imunify360/imunify360.config`, and its documentation says changes there apply automatically without a restart. You can also change them with `imunify360-agent config update`. Check the current values first:

```
imunify360-agent config show
```

### Ports

In the `FIREWALL` section, `port_blocking_mode` is `ALLOW` (default: everything open except listed ports) or `DENY` (everything closed except listed ports). The allowed ports are set per direction and protocol: `TCP_IN_IPv4`, `TCP_OUT_IPv4`, `UDP_IN_IPv4`, `UDP_OUT_IPv4` and the matching `_IPv6` keys. To match a CSF-style “only these ports” policy:

- Copy your CSF `TCP_IN`/`UDP_IN` lists into the matching Imunify360 keys (in the Imunify360 settings UI, or in the config file using the same format `config show` prints).

- Check that SSH, the panel ports, mail ports and anything custom (monitoring agents, backups) are in the list.

- Only then switch `port_blocking_mode` to `DENY`:

```
imunify360-agent config update '{"FIREWALL": {"port_blocking_mode": "DENY"}}'
```

For one-off closures in ALLOW mode, block a single port and allow exceptions per IP:

```
imunify360-agent blocked-port add 3306:tcp --comment "no public MySQL"
imunify360-agent blocked-port-ip add 3306:tcp --ips 192.0.2.50 --comment "app server"
```

### DoS protection

The `DOS` section is enabled by default with `interval` 30 seconds and `default_limit` 250 connections from one IP to a local port (minimum 100). `port_limits` sets other thresholds per port. Raise limits for ports that legitimately get many connections from one address, such as a proxy or a CDN that does not pass client IPs.

### Outgoing SMTP

CSF’s `SMTP_BLOCK` has a counterpart in the `SMTP_BLOCKING` section, which is **off by default**. Its defaults: ports 25, 587 and 465, `allow_groups` = mail, `allow_users` empty, `allow_local` and `redirect` off. If you used SMTP_BLOCK to stop scripts from sending mail directly, turn it on:

```
imunify360-agent config update '{"SMTP_BLOCKING": {"enable": true}}'
```

Add any users you allowed in CSF’s `SMTP_ALLOWUSER` to `allow_users`. On cPanel you can use WHM’s own SMTP Restrictions instead, but not both.

## WHM Security Advisor warnings after CSF is gone

Security Advisor was built with CSF in mind and does not always read Imunify360’s firewall state. Known cases from cPanel’s community and case tracker:

- **MySQL listening on all interfaces:** after removing CSF, Security Advisor warns that MariaDB/MySQL is exposed even though Imunify360 blocks port 3306. In September 2025 cPanel staff confirmed it as a false positive and linked it to case CPANEL-48877. The suggested workaround, `bind-address = 127.0.0.1`, only fits servers where no customer needs remote database access.

- **“No brute force protection”:** an older false positive while Imunify360 was active (CPANEL-40545), marked resolved in cPanel 112. If you see it on a current version, check that Imunify360 is licensed and running.

Before you dismiss a warning, prove the port is closed from outside, for example from another server:

```
nc -vz -w 3 203.0.113.10 3306
```

## Check that it worked

```
systemctl is-active imunify360 csf lfd      # expect: active, inactive, inactive
imunify360-agent rstatus
imunify360-agent ip-list local list --purpose white
imunify360-agent blocked-port list
```

- SSH, panel, web and mail ports answer from outside; closed ports (3306, internal services) do not.

- A test IP added with `--purpose drop` is blocked, and removing it unblocks.

- If SMTP blocking is on, a PHP script that connects directly to an outside port 25 fails, while mail through Exim still works.

- Security Advisor shows only the known false positives above.

## Common problems

- **Locked out after switching to DENY:** the SSH or panel port was missing from `TCP_IN_IPv4`. Use the provider console, add the port, and confirm your IP is on the White List.

- **Blocked Ports page still greyed out:** CSF is still running or enabled. Check `systemctl is-active csf lfd`.

- **Monitoring alerts stop:** outgoing ports for monitoring or backup agents were open in CSF’s `TCP_OUT` but not in Imunify360. Add them.

- **Mail from a script stopped:** SMTP blocking is on and the script’s user is not in `allow_users`.

**Official documentation:** [Imunify360: CSF integration](https://docs.imunify360.com/ids_integration/) · [Imunify360: Config file description](https://docs.imunify360.com/config_file_description/) · [Imunify360: Command-line interface](https://docs.imunify360.com/command_line_interface/) · [cPanel: Are Imunify360 and CSF compatible?](https://support.cpanel.net/hc/en-us/articles/29352568422295-Are-Imunify360-and-CSF-compatible)

**Related:** [CSF Fork 2026: Which Reliable Replacement After ConfigServer?](/guides/csf-fork-2026-after-configserver/) · [CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting](/guides/crowdsec-vs-imunify360-vs-bitninja/) · [Imunify360 Whitelist IP and Countries from the CLI: Commands](/guides/imunify360-whitelist-ip-cli/) · [Replace CSF with firewalld and fail2ban: Secure Step-by-Step](/guides/replace-csf-with-firewalld-fail2ban/) · [Imunify360 review: worth it on a shared cPanel server?](/reviews/imunify360-review/)

**See also:** [CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans](/guides/csf-commands-cheat-sheet/) · [Open Port Checker: Test TCP Ports on Any Public Server](/tools/open-port-checker/) · [Imunify360 False Positives: Find the Rule ID and Fix It](/guides/imunify360-false-positives/)

## Frequently asked questions

### Can Imunify360 replace CSF completely?

Yes. Imunify360 has its own firewall, port blocking, DoS protection and SMTP traffic manager. Those features turn on when CSF is not running.

### Does Imunify360 import csf.allow and csf.deny?

Not automatically while CSF runs. Use the migrate_csf tool before disabling CSF, then check the White and Black Lists.

### Which ports does Imunify360 block by default?

Port blocking starts in ALLOW mode, so everything is open except ports you add. Switch to DENY mode only after listing every port you need.

### Why does Security Advisor say MySQL is exposed after removing CSF?

cPanel confirmed this as a false positive (CPANEL-48877): Security Advisor does not read Imunify360’s rules. Test the port from outside to be sure.

### Do I need cPHulk if I run Imunify360?

cPanel staff have said Imunify360 does what cPHulk does and both do not need to be enabled.
