Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

Install CSF Firewall on a WHM/cPanel Server

This guide shows you how to install ConfigServer Security and Firewall (CSF) on a server that runs WHM and cPanel. You need root access, so it is for VPS and dedicated server customers.

SSL and Security2 min read10 steps14 screenshots

What is CSF?

A firewall is like a security guard at the door of your server. It decides which visitors may come in. CSF is a free firewall tool for Linux servers. It blocks bad traffic, watches for hacking attempts and plugs into WHM. WHM is the admin panel for the whole server. cPanel is the panel for a single hosting account.

Ask Hostvento support if CSF is already on your plan, or if you should install it yourself.

Before you start

A wrong firewall rule can lock you out of your own server. Make sure you know how to reach the server another way, such as a console from your provider. Keep your own IP address handy so you can allow it.

Steps

  1. Log in to your server with SSH as root.
    Screenshot: Log in to your server with SSH as root.
    Screenshot: Log in to your server with SSH as root.
  2. Go to a temporary folder:
    cd /usr/src
  3. Download CSF:
    wget https://download.configserver.com/csf.tgz
    This saves the CSF package to the server.
    Screenshot: Download CSF: wget https://download.configserver.com/csf.tgz This saves the CSF package to
    Screenshot: Download CSF: wget https://download.configserver.com/csf.tgz This saves the CSF package to
  4. Unpack it:
    tar -xzf csf.tgz
  5. Go into the new folder:
    cd csf
  6. Run the installer:
    sh install.sh
  7. Test that your server supports CSF:
    perl /usr/local/csf/bin/csftest.pl
    You should see "RESULT: csf should function on this server".
  8. Log in to WHM.
  9. In the search box on the left, type ConfigServer Security & Firewall and click it.
    Screenshot: In the search box on the left, type ConfigServer Security & Firewall and click it.
    Screenshot: In the search box on the left, type ConfigServer Security & Firewall and click it.
    Screenshot: In the search box on the left, type ConfigServer Security & Firewall and click it.
    Screenshot: In the search box on the left, type ConfigServer Security & Firewall and click it.
  10. Click Firewall Configuration to see the settings.

Important first settings

CSF starts in testing mode. In this mode it clears its rules every few minutes, so you cannot lock yourself out by mistake. When you are sure all is fine, open the configuration and set TESTING to 0. Then click Change and restart CSF.

Screenshot: CSF starts in testing mode . In this mode it clears its rules every few minutes, so you ca
Screenshot: CSF starts in testing mode . In this mode it clears its rules every few minutes, so you ca
Screenshot: CSF starts in testing mode . In this mode it clears its rules every few minutes, so you ca
Screenshot: CSF starts in testing mode . In this mode it clears its rules every few minutes, so you ca

Check the list of open ports. Keep the ports you need open, such as 80, 443, 22 for SSH and the cPanel and WHM ports.

Tip: Add your own IP address to the allow list using Quick Allow in the CSF screen. This keeps you from being blocked.

Quick recap

  • CSF is a free firewall that works inside WHM.
    Screenshot: CSF is a free firewall that works inside WHM.
  • Download it, unpack it and run sh install.sh as root.
  • Open it in WHM through ConfigServer Security & Firewall.
  • Allow your own IP before you turn off testing mode.
    Screenshot: Allow your own IP before you turn off testing mode.