Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to install and set up CSF on AlmaLinux

This guide shows you how to install the CSF firewall on an AlmaLinux server and set it up. It needs root access, so it is for VPS and dedicated server customers.

How-To Guides2 min read10 steps

What is CSF?

A firewall is like a guard at a door. It decides which visitors may come in. CSF stands for ConfigServer Security and Firewall. It is a free firewall tool for Linux servers. AlmaLinux is a free Linux system often used for servers.

Root access means you are the main administrator of the server. Log in as root, or use sudo before each command.

Before you start

Make sure you have a second way into the server, such as a console in your client area. A wrong firewall rule can lock you out. Also note your own IP address.

Steps

  1. Connect to your server with SSH (a safe way to type commands on a remote server).
  2. Install the tools CSF needs:
dnf install -y wget perl perl-libwww-perl perl-LWP-Protocol-https perl-GDGraph tar

This installs the helper programs.

  1. Download CSF from the official ConfigServer download address:
cd /usr/src
wget https://download.configserver.com/csf.tgz

This saves the CSF package on your server. If the address has moved, check the CSF project page for the current one.

  1. Unpack and install it:
tar -xzf csf.tgz
cd csf
sh install.sh

This runs the installer.

  1. Test that the server can run CSF:
perl /usr/local/csf/bin/csftest.pl

It should say "RESULT: csf should function on this server".

  1. Open the settings file:
nano /etc/csf/csf.conf
  1. Set TESTING = "1" while you try it. In this mode, rules clear themselves every few minutes, so a mistake will not lock you out for long.
  2. Find TCP_IN. This is the list of ports (numbered doors) that are open for incoming traffic. Keep SSH (22, or your own SSH port) and add ones you need, such as 80 and 443 for websites.
  3. Save the file and apply it:
csf -r

This restarts the firewall with your new rules.

  1. Check that you can still log in with a new SSH window. If all is well, change TESTING to "0", save, and run csf -r again.

Useful commands

  • csf -a 203.0.113.5 allows an IP address.
  • csf -d 203.0.113.5 blocks an IP address.
  • csf -x turns CSF off. csf -e turns it on.
Tip: Add your own IP to the allow list first with csf -a.

Quick recap

  • CSF is a free firewall for Linux servers.
  • You need root access.
  • Install helper tools, download CSF, and run install.sh.
  • Keep TESTING on until you know you can still log in.
  • Open only the ports you need, then restart with csf -r.