The ConfigServer Security & Firewall (CSF) is a powerful firewall application integrated with WebHost Manager (WHM). It helps you block and unblock IP addresses, manage ports, and protect your server against brute‑force attacks and suspicious activity.

 

Why Use CSF?

  • Protects your server from unauthorized access.

  • Blocks suspicious IP addresses automatically.

  • Allows you to whitelist trusted IPs.

  • Provides granular control over incoming and outgoing connections.

  • Integrates with WHM for easy management.

 

Common CSF Tasks

1. Unblocking an IP Address

  1. Log in to WHM.

  2. In the search box, type configserver and click ConfigServer Security & Firewall.

  3. Under Search iptables for IP address, enter the IP you want to check.

  4. If blocked, the IP will appear with the reason.

  5. Click the padlock icon to unblock it.

 

2. Whitelisting an IP Address

  1. In WHM, go to ConfigServer Security & Firewall.

  2. Under Quick Allow, enter the IP address.

  3. (Optional) Add a comment for reference.

  4. Click Quick Allow. This adds the IP to the csf.allow list.

 

3. Using Quick Ignore

  • If an IP continues to be blocked by the Login Failure Daemon (LFD) despite being whitelisted, add it to the Quick Ignore list.

  • This prevents LFD from blocking the IP for suspicious activity. ⚠️ Use only as a temporary measure while resolving the underlying issue.

 

4. Checking cPHulk

  • WHM’s cPHulk Brute Force Protection can block IPs independently of CSF.

  • To check:

    1. In WHM, search for cphulk.

    2. Click cPHulk Brute Force Protection.

    3. Use the History Reports tab to view blocked IPs, users, or failed logins.

    4. Remove blocks if necessary.

 

5. Opening and Closing Ports

  1. In WHM, go to ConfigServer Security & Firewall → Firewall Configuration.

  2. Scroll to IPv4 Port Settings.

  3. Configure:

    • TCP_IN → Allowed incoming TCP ports.

    • TCP_OUT → Allowed outgoing TCP ports.

    • UDP_IN → Allowed incoming UDP ports.

    • UDP_OUT → Allowed outgoing UDP ports.

  4. Click Change and then Restart csf+lfd to apply changes.

 

Security Best Practices

  • Only whitelist IPs when absolutely necessary.

  • Regularly review blocked IPs to detect suspicious activity.

  • Keep ports closed unless required for specific services.

  • Use cPHulk alongside CSF for layered protection.

  • Always restart CSF after making configuration changes.

 

More information

For more information about CSF, please visit https://configserver.com/cp/csf.html.

Hasznosnak találta ezt a választ? 0 A felhasználók hasznosnak találták ezt (0 Szavazat)

Powered by WHMCompleteSolution