Short answer: Imunify360 can be the only firewall on a cPanel or DirectAdmin server. While CSF is running, Imunify360 switches off its own Blocked Ports, DoS Protection and SMTP Traffic Manager; once CSF is gone those features take over. Back up your CSF lists, run Imunify360’s migrate_csf tool, disable CSF with csf -x and systemctl disable csf lfd, then set port rules and SMTP blocking in Imunify360. Expect a false “MySQL listening on all interfaces” warning in WHM Security Advisor.
Commands checked against the official Imunify360 documentation and cPanel knowledge base (linked below) on 6 October 2026; not yet run on our lab servers (our cPanel lab runs ImunifyAV, not Imunify360).
Table of Contents
What changes when CSF is removed
Imunify360 and CSF are compatible, and both cPanel and CloudLinux say so. When Imunify360 detects CSF it hands three jobs to CSF and turns its own versions off:
| Feature | With CSF running | After CSF is removed |
|---|---|---|
| Open/closed ports | CSF TCP_IN/TCP_OUT in csf.conf | Imunify360 Blocked Ports (FIREWALL section) |
| Connection-flood (DoS) blocking | CSF/LFD settings | Imunify360 DoS Protection (DOS section) |
| Outgoing SMTP restriction | CSF SMTP_BLOCK | Imunify360 SMTP Traffic Manager (SMTP_BLOCKING section) |
| Allow/deny lists | csf.allow, csf.deny, csf.ignore | Imunify360 White List and Black List |
| Login brute force | LFD (plus cPHulk) | Imunify360 (cPanel staff note it does the job of cPHulk) |
Two details catch people out. First, CSF’s allow, deny and ignore lists are not imported automatically while both run; Imunify360 simply avoids blocking addresses in CSF’s allow and ignore lists. Second, Imunify360’s port blocking starts in ALLOW mode, where everything is open except what you list. CSF setups are usually the opposite (only listed ports open), so check the mode after the switch.
Back up CSF before you change anything
mkdir -p /root/csf-backup-$(date +%F)
cp -a /etc/csf/csf.conf /etc/csf/csf.allow /etc/csf/csf.deny /etc/csf/csf.ignore \
/root/csf-backup-$(date +%F)/
grep -E "^(TCP_IN|TCP_OUT|UDP_IN|UDP_OUT|TCP6_IN|SMTP_BLOCK|SMTP_ALLOWUSER)" /etc/csf/csf.conf
Keep that grep output: it is your list of ports and SMTP rules to recreate. Then make sure you cannot lock yourself out. Add your office or VPN address (198.51.100.25 here) to the Imunify360 White List first:
imunify360-agent ip-list local add --purpose white 198.51.100.25 --comment "admin office"
imunify360-agent ip-list local list --purpose white --by-ip 198.51.100.25
Run the migrate_csf tool, then disable CSF
Imunify360 includes a migration tool. The documented commands are:
cd /opt/imunify360/venv/share/imunify360/scripts/migrate_csf
./main.py
less /var/log/imunify360/migrate_csf.log
Imunify360’s documentation does not list exactly which CSF settings the tool converts, so read its log and compare the result with your backup. Check at least the white list, the black list and the ports:
imunify360-agent ip-list local list --purpose white
imunify360-agent ip-list local list --purpose drop
imunify360-agent blocked-port list
When the lists look right, disable CSF so Imunify360’s firewall takes over. These are the commands Imunify360 documents:
csf -x
systemctl disable csf
systemctl disable lfd
Do this from a console or a session you know is whitelisted, and have provider console access ready. Removing the CSF package itself can wait a week; disabled CSF is easy to bring back with csf -e if something goes wrong.
Recreate port rules, DoS and SMTP blocking
Imunify360’s settings live in /etc/sysconfig/imunify360/imunify360.config, and its documentation says changes there apply automatically without a restart. You can also change them with imunify360-agent config update. Check the current values first:
imunify360-agent config show
Ports
In the FIREWALL section, port_blocking_mode is ALLOW (default: everything open except listed ports) or DENY (everything closed except listed ports). The allowed ports are set per direction and protocol: TCP_IN_IPv4, TCP_OUT_IPv4, UDP_IN_IPv4, UDP_OUT_IPv4 and the matching _IPv6 keys. To match a CSF-style “only these ports” policy:
- Copy your CSF
TCP_IN/UDP_INlists into the matching Imunify360 keys (in the Imunify360 settings UI, or in the config file using the same formatconfig showprints). - Check that SSH, the panel ports, mail ports and anything custom (monitoring agents, backups) are in the list.
- Only then switch
port_blocking_modetoDENY:
imunify360-agent config update '{"FIREWALL": {"port_blocking_mode": "DENY"}}'
For one-off closures in ALLOW mode, block a single port and allow exceptions per IP:
imunify360-agent blocked-port add 3306:tcp --comment "no public MySQL"
imunify360-agent blocked-port-ip add 3306:tcp --ips 192.0.2.50 --comment "app server"
DoS protection
The DOS section is enabled by default with interval 30 seconds and default_limit 250 connections from one IP to a local port (minimum 100). port_limits sets other thresholds per port. Raise limits for ports that legitimately get many connections from one address, such as a proxy or a CDN that does not pass client IPs.
Outgoing SMTP
CSF’s SMTP_BLOCK has a counterpart in the SMTP_BLOCKING section, which is off by default. Its defaults: ports 25, 587 and 465, allow_groups = mail, allow_users empty, allow_local and redirect off. If you used SMTP_BLOCK to stop scripts from sending mail directly, turn it on:
imunify360-agent config update '{"SMTP_BLOCKING": {"enable": true}}'
Add any users you allowed in CSF’s SMTP_ALLOWUSER to allow_users. On cPanel you can use WHM’s own SMTP Restrictions instead, but not both.
WHM Security Advisor warnings after CSF is gone
Security Advisor was built with CSF in mind and does not always read Imunify360’s firewall state. Known cases from cPanel’s community and case tracker:
- MySQL listening on all interfaces: after removing CSF, Security Advisor warns that MariaDB/MySQL is exposed even though Imunify360 blocks port 3306. In September 2025 cPanel staff confirmed it as a false positive and linked it to case CPANEL-48877. The suggested workaround,
bind-address = 127.0.0.1, only fits servers where no customer needs remote database access. - “No brute force protection”: an older false positive while Imunify360 was active (CPANEL-40545), marked resolved in cPanel 112. If you see it on a current version, check that Imunify360 is licensed and running.
Before you dismiss a warning, prove the port is closed from outside, for example from another server:
nc -vz -w 3 203.0.113.10 3306
Check that it worked
systemctl is-active imunify360 csf lfd # expect: active, inactive, inactive
imunify360-agent rstatus
imunify360-agent ip-list local list --purpose white
imunify360-agent blocked-port list
- SSH, panel, web and mail ports answer from outside; closed ports (3306, internal services) do not.
- A test IP added with
--purpose dropis blocked, and removing it unblocks. - If SMTP blocking is on, a PHP script that connects directly to an outside port 25 fails, while mail through Exim still works.
- Security Advisor shows only the known false positives above.
Common problems
- Locked out after switching to DENY: the SSH or panel port was missing from
TCP_IN_IPv4. Use the provider console, add the port, and confirm your IP is on the White List. - Blocked Ports page still greyed out: CSF is still running or enabled. Check
systemctl is-active csf lfd. - Monitoring alerts stop: outgoing ports for monitoring or backup agents were open in CSF’s
TCP_OUTbut not in Imunify360. Add them. - Mail from a script stopped: SMTP blocking is on and the script’s user is not in
allow_users.
Official documentation: Imunify360: CSF integration · Imunify360: Config file description · Imunify360: Command-line interface · cPanel: Are Imunify360 and CSF compatible?
Related: CSF Fork 2026: Which Reliable Replacement After ConfigServer? · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting · Imunify360 Whitelist IP and Countries from the CLI: Commands · Replace CSF with firewalld and fail2ban: Secure Step-by-Step · Imunify360 review: worth it on a shared cPanel server?
See also: CSF Commands Cheat Sheet: Allow, Deny, Ports and Tempbans · Open Port Checker: Test TCP Ports on Any Public Server · Imunify360 False Positives: Find the Rule ID and Fix It
Frequently asked questions
Can Imunify360 replace CSF completely?
Yes. Imunify360 has its own firewall, port blocking, DoS protection and SMTP traffic manager. Those features turn on when CSF is not running.
Does Imunify360 import csf.allow and csf.deny?
Not automatically while CSF runs. Use the migrate_csf tool before disabling CSF, then check the White and Black Lists.
Which ports does Imunify360 block by default?
Port blocking starts in ALLOW mode, so everything is open except ports you add. Switch to DENY mode only after listing every port you need.
Why does Security Advisor say MySQL is exposed after removing CSF?
cPanel confirmed this as a false positive (CPANEL-48877): Security Advisor does not read Imunify360’s rules. Test the port from outside to be sure.
Do I need cPHulk if I run Imunify360?
cPanel staff have said Imunify360 does what cPHulk does and both do not need to be enabled.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Last full review
- Next review