# Installing Sentinel Firewall as a drop-in CSF replacement on Ubuntu 24.04 and Debian 13

Source: https://srvscripts.com/guides/sentinel-firewall-csf-replacement/
Updated: 2026-10-03
Publisher: srvScripts (https://srvscripts.com/)

Sentinel Firewall is the OpenPanel project’s answer to the ConfigServer shutdown: a firewall and log-watcher that reads the same configuration files as CSF, answers to the same command-line flags, and is packaged for Ubuntu 22.04 through 25.x, Debian 12 and 13, and EL 8 to 10. On Debian-family servers, where CSF was always a slightly awkward fit, it is the least disruptive way to get back onto a maintained codebase without rewriting a decade of rules. This tutorial covers Ubuntu 24.04 and Debian 13 specifically.

In short: Back up /etc/csf, run csf -x and the original uninstall.sh, restore the configuration directory, then download, read and run the Sentinel installer, which imports the existing csf.conf, csf.allow and csf.deny.

**Short answer:** Back up `/etc/csf`, run `csf -x` and the original `uninstall.sh`, restore the configuration directory, then download, read and run the Sentinel installer, which imports the existing `csf.conf`, `csf.allow` and `csf.deny`. Set `TESTING = "0"`, fix the log paths for the journal or rsyslog, mask ufw and the plain nftables unit, and start with `csf -ra`. Confirm with `csf -v` reporting Sentinel, `nft list ruleset` showing your ports, and a test address being blocked after a few failed SSH logins.

## Before you start

Make sure the server is up to date and that you have console access independent of SSH. Then record the current state of CSF so you can compare afterwards:

```
apt update && apt full-upgrade -y
csf -v
cp -a /etc/csf /root/csf-backup-$(date +%F)
csf -l > /root/csf-rules-before.txt
```

Sentinel reuses `/etc/csf/`, so the backup is your rollback. Also note whether ufw or nftables has a unit enabled; a stock Ubuntu 24.04 cloud image often has ufw installed but inactive:

```
systemctl is-enabled ufw nftables 2>/dev/null
```

Both should be disabled before installing any CSF-style firewall.

## Remove CSF

Stop the daemons, flush the rules and run the original uninstaller. Leave the configuration directory in place; the uninstaller removes binaries and cron entries but you want `csf.conf`, `csf.allow` and `csf.deny` to survive:

```
csf -x
cp -a /root/csf-backup-$(date +%F) /root/csf-keep
sh /etc/csf/uninstall.sh
cp -a /root/csf-keep /etc/csf
pgrep -a lfd
```

If `pgrep` still shows an lfd process, kill it before proceeding; two log watchers on one box produce doubled blocks and confusing logs.

## Install Sentinel

Sentinel is distributed from its own project site as an installer script; fetch it, inspect it, then run it. Do not pipe an unread script into a shell on a production server:

```
cd /root
curl -fsSLO https://sentinel.openpanel.org/install.sh  # check the project page for the current URL
less install.sh
bash install.sh
```

The installer detects an existing `/etc/csf/` and imports it. On Debian 13 it pulls in `nftables`, `libwww-perl` and a handful of Perl modules through apt; on Ubuntu 24.04 the dependency list is the same. When it finishes you should have `csf` and `lfd` commands that are actually Sentinel binaries, plus systemd units:

```
csf -v
systemctl status csf lfd --no-pager
```

The version string identifies Sentinel rather than ConfigServer. If the installer reports it could not import a setting, that setting is one Sentinel does not implement; check the project changelog for the option’s status rather than assuming it is silently supported.

## Review the imported configuration

Sentinel honours the key options: `TCP_IN`, `TCP_OUT`, `UDP_IN`, `UDP_OUT`, the `LF_*` login-failure triggers, `CT_LIMIT`, `DENY_IP_LIMIT` and the allow and deny files. Debian-family servers log SSH and mail to the journal, so confirm the log paths point at what actually exists:

```
grep -E '^(SSHD_LOG|SMTPAUTH_LOG|POP3D_LOG|IMAPD_LOG|FTPD_LOG|CUSTOM1_LOG) ' /etc/csf/csf.conf
ls -la /var/log/auth.log /var/log/mail.log 2>/dev/null
```

On Ubuntu 24.04 `rsyslog` is installed by default and `/var/log/auth.log` exists. On a minimal Debian 13 install it may not; either install `rsyslog` or set the log paths to the journal export Sentinel supports (see its documentation for the exact syntax for your build). While you are in the file, apply the post-2026 hardening from our [CSF hardening guide](/guides/hardening-csf-messenger-remote-lists/):

```
MESSENGER = "0"
UI = "0"
RESTRICT_SYSLOG = "3"
TESTING = "0"
```

`TESTING = "0"` matters: Sentinel, like CSF, ships in testing mode with a cron that flushes rules every few minutes, and the firewall is not real until you turn it off.

## Start and check the rules land in nftables

```
csf -ra
nft list tables
nft list ruleset | grep -c dport
```

Sentinel writes native nftables on Debian 13 and Ubuntu 24.04 rather than going through the iptables-nft shim, so `nft list ruleset` is the source of truth. Compare the port list against your before snapshot:

```
csf -l > /root/csf-rules-after.txt
diff
