Sentinel Firewall is the OpenPanel project’s answer to the ConfigServer shutdown: a firewall and log-watcher that reads the same configuration files as CSF, answers to the same command-line flags, and is packaged for Ubuntu 22.04 through 25.x, Debian 12 and 13, and EL 8 to 10. On Debian-family servers, where CSF was always a slightly awkward fit, it is the least disruptive way to get back onto a maintained codebase without rewriting a decade of rules. This tutorial covers Ubuntu 24.04 and Debian 13 specifically.
Applies to Ubuntu 24.04 and Debian 13
Table of Contents
Short answer: Back up /etc/csf, run csf -x and the original uninstall.sh, restore the configuration directory, then download, read and run the Sentinel installer, which imports the existing csf.conf, csf.allow and csf.deny. Set TESTING = "0", fix the log paths for the journal or rsyslog, mask ufw and the plain nftables unit, and start with csf -ra. Confirm with csf -v reporting Sentinel, nft list ruleset showing your ports, and a test address being blocked after a few failed SSH logins.
Before you start
Make sure the server is up to date and that you have console access independent of SSH. Then record the current state of CSF so you can compare afterwards:
apt update && apt full-upgrade -y
csf -v
cp -a /etc/csf /root/csf-backup-$(date +%F)
csf -l > /root/csf-rules-before.txt
Sentinel reuses /etc/csf/, so the backup is your rollback. Also note whether ufw or nftables has a unit enabled; a stock Ubuntu 24.04 cloud image often has ufw installed but inactive:
systemctl is-enabled ufw nftables 2>/dev/null
Both should be disabled before installing any CSF-style firewall.
Remove CSF
Stop the daemons, flush the rules and run the original uninstaller. Leave the configuration directory in place; the uninstaller removes binaries and cron entries but you want csf.conf, csf.allow and csf.deny to survive:
csf -x
cp -a /root/csf-backup-$(date +%F) /root/csf-keep
sh /etc/csf/uninstall.sh
cp -a /root/csf-keep /etc/csf
pgrep -a lfd
If pgrep still shows an lfd process, kill it before proceeding; two log watchers on one box produce doubled blocks and confusing logs.
Install Sentinel
Sentinel is distributed from its own project site as an installer script; fetch it, inspect it, then run it. Do not pipe an unread script into a shell on a production server:
cd /root
curl -fsSLO https://sentinel.openpanel.org/install.sh # check the project page for the current URL
less install.sh
bash install.sh
The installer detects an existing /etc/csf/ and imports it. On Debian 13 it pulls in nftables, libwww-perl and a handful of Perl modules through apt; on Ubuntu 24.04 the dependency list is the same. When it finishes you should have csf and lfd commands that are actually Sentinel binaries, plus systemd units:
csf -v
systemctl status csf lfd --no-pager
The version string identifies Sentinel rather than ConfigServer. If the installer reports it could not import a setting, that setting is one Sentinel does not implement; check the project changelog for the option’s status rather than assuming it is silently supported.
Review the imported configuration
Sentinel honours the key options: TCP_IN, TCP_OUT, UDP_IN, UDP_OUT, the LF_* login-failure triggers, CT_LIMIT, DENY_IP_LIMIT and the allow and deny files. Debian-family servers log SSH and mail to the journal, so confirm the log paths point at what actually exists:
grep -E '^(SSHD_LOG|SMTPAUTH_LOG|POP3D_LOG|IMAPD_LOG|FTPD_LOG|CUSTOM1_LOG) ' /etc/csf/csf.conf
ls -la /var/log/auth.log /var/log/mail.log 2>/dev/null
On Ubuntu 24.04 rsyslog is installed by default and /var/log/auth.log exists. On a minimal Debian 13 install it may not; either install rsyslog or set the log paths to the journal export Sentinel supports (see its documentation for the exact syntax for your build). While you are in the file, apply the post-2026 hardening from our CSF hardening guide:
MESSENGER = "0"
UI = "0"
RESTRICT_SYSLOG = "3"
TESTING = "0"
TESTING = "0" matters: Sentinel, like CSF, ships in testing mode with a cron that flushes rules every few minutes, and the firewall is not real until you turn it off.
Start and check the rules land in nftables
csf -ra
nft list tables
nft list ruleset | grep -c dport
Sentinel writes native nftables on Debian 13 and Ubuntu 24.04 rather than going through the iptables-nft shim, so nft list ruleset is the source of truth. Compare the port list against your before snapshot:
csf -l > /root/csf-rules-after.txt
diff <(grep -oE 'dpt:[0-9]+' /root/csf-rules-before.txt | sort -u) <(grep -oE 'dport [0-9]+' /root/csf-rules-after.txt | grep -oE '[0-9]+' | sort -u)
The formats differ between the old iptables output and nftables output, so the diff is approximate, but any port present in one list and absent from the other deserves a look.
Common pitfall
On Ubuntu, ufw is packaged with an nftables backend and, even when inactive, an unattended upgrade or a well-meaning colleague can enable it and layer a second ruleset on top of Sentinel’s. Mask it:
systemctl disable --now ufw
systemctl mask ufw
The same applies to the plain nftables.service unit, which loads /etc/nftables.conf at boot and would flush Sentinel’s tables if that file contains a flush ruleset line.
Verify
Generate a few failed SSH logins from a test address, then confirm the block appears in both Sentinel’s records and the kernel:
tail -f /var/log/lfd.log
csf -g 203.0.113.10
nft list ruleset | grep 203.0.113.10
Reboot once in a maintenance window and repeat nft list tables; the firewall must come back on its own. Record the Sentinel version in your inventory and check its project releases monthly, since it is now the piece of software standing between your SSH port and the internet.
Sentinel Firewall at a glance

Official documentation: AlmaLinux wiki, Linux man pages.
Related guides: Replacing CSF with firewalld + fail2ban on AlmaLinux 9/10, step by step · CVE-2026-65638, 65639 and 67402 explained: patching the CSF Messenger and URLGET remote-code flaws · CrowdSec vs Imunify360 vs BitNinja: choosing a post-CSF security stack for shared hosting.
Frequently asked questions
Does Sentinel Firewall use the same csf.conf and commands as CSF?
Yes. Sentinel reads /etc/csf/csf.conf, csf.allow and csf.deny, and its csf and lfd binaries accept the familiar flags such as csf -ra, csf -g and csf -d. Options it does not implement are reported during import, so read the installer output rather than assuming every setting carried over.
Does Sentinel work with nftables on Debian 13 and Ubuntu 24.04?
It writes native nftables rules on both, so nft list ruleset is the source of truth rather than iptables -L. Disable and mask ufw and the stock nftables.service first, because either can flush or layer over Sentinel’s tables.
Can I go back to CSF after installing Sentinel?
Yes, as long as you kept the /etc/csf backup taken before the swap. Stop Sentinel, remove its packages, restore the directory and reinstall CSF from your archived installer, remembering that ConfigServer no longer publishes updates and the cPanel or DirectAdmin forks only target those panels.
Maintenance record
This guide changes servers, data or security settings, so we re-check it against current versions on a fixed schedule. Take a backup or snapshot before you start.
- Maintained by
- srvScripts editorial team
- Supported versions
- Ubuntu 24.04 and Debian 13
- Last full review
- Next review
- Sources
- wiki.almalinux.org