CSF 2.1 · cPanel Shield Firewall · Stable

The firewall the modern cPanel server deserves.

A cPanel-first firewall built on native nftables, IPv4 + IPv6, an event-driven LFD 2.0, and live Threat Intelligence - part of UnderShield. Version 2.1.5 stable is available now, free and open source.

2.1.5 is the current stable release - feature-complete, unit-tested, and validated on live cPanel servers. GPL-3.0.

Part ofUnderShieldcPanel & WHMnftables · inetIPv4 + IPv6Stable · 2.1.5
What's inside

Keep the CSF workflow. Rebuild the foundation.

Every capability below ships in the 2.1.5 stable release, backed by a 460+ assertion automated test suite and validated on live cPanel servers.

01 / ENGINE

nftables-first architecture

A single table inet csf with dynamic, timeout-capable sets - IPv4 and IPv6 in one model. Blocking one IP updates a set element, never a rebuild.

Stable
02 / DETECTION

LFD 2.0

An event-driven detection layer with modular collectors, incremental log tailing, temporary blocks with native set timeouts, and a clear reason behind every action.

Stable
03 / CPANEL

cPanel-native focus

Service and version detection, cPHulk and ModSecurity awareness, automatic SSH/cPanel port presets on install, and a WHM interface registered through AppConfig.

Stable
04 / INTELLIGENCE

Threat Intelligence feeds

Reputable IP/CIDR feeds (Spamhaus DROP, Feodo C2, CINS, IPsum, Blocklist.de) load into dedicated nftables sets with per-feed toggles and category policies - inbound, outbound, or both.

Stable
05 / SAFETY

Safe administration

Atomic rule changes, a lockout guard that checks your live SSH session, and a --safe-reload watchdog that auto-reverts if you can't confirm.

Stable
06 / UPDATES

One-click WHM updater

The WHM interface checks the release channel, then downloads, SHA-256 verifies, and installs new versions in place with a live progress bar - your config and lists preserved.

Stable
How it works

From service signal to a dropped packet.

The path a request takes through CSF 2.1 - traceable steps, explainable decisions, no opaque automation.

01Attack

Suspicious activity reaches a protected service.

02Service event

A log line records an actionable signal.

03LFD 2.0

Collectors normalise it into a structured event.

04Correlation

The risk engine scores the source and checks thresholds.

05nftables set

The IP is added to a set with a timeout.

06Drop

Traffic is dropped in-kernel before it reaches the service.

LFD 2.0

Detection built for hosting reality.

Modular collectors watch the parts of a cPanel server that matter most and feed a single correlation engine, so a distributed attacker is recognised as one hostile actor and enforced progressively.

SSH, Exim, Dovecot, FTP, web-server and WAF signals are parsed by independent detectors into normalised events.
Temporary blocks with native nftables timeouts and a clear operator-facing reason for every action.
ModSecurity / OWASP CRS correlation escalates repeat, high-confidence WAF attacks to a network-layer block.
lfd 2.0 - event to enforcement
service      sshd
event        authentication_failure
source       185.203.44.19
score        72 / short block

action       add to csf_temp4 (timeout 300s)
reason       LFD: sshd auth_failure (score 72)
csf - familiar commands, modern engine
# csf -a 203.0.113.7      # allow
# csf -td 198.51.100.9 3600 # temporary deny
# csf -g 198.51.100.9      # inspect
# csf --safe-reload         # apply, auto-revert
# csf --self-update         # update in place

The familiar commands you know, on a native
nftables engine. Legacy csf.conf is migrated.
CLI compatibility

Same CSF philosophy. Modern Linux foundation.

Your operational muscle memory carries over. The familiar commands and configuration files drive a native nftables engine underneath.

Preserved: csf -a · -d · -td · -tr · -dr · -g · -r
Modern: csf inspect · health · migrate · --safe-reload · --self-update
Files in scope: csf.conf · csf.allow · csf.deny · csf.ignore
Compatibility

cPanel-first, with support claims kept honest.

CSF 2.1 runs on the modern Linux distributions cPanel & WHM support, with first-class nftables on EL8/9/10. Ubuntu is supported on the same nftables engine (community beta).

Operating systems

AlmaLinux 8 / 9 / 10Supported
CloudLinux 8 / 9 / 10Supported
RHEL / Rocky 8 / 9 / 10Supported
Ubuntu 22.04 / 24.04 LTSSupported · beta

Hosting integrations

cPanel & WHMSupported
nftables / inetImplemented
ModSecurity / OWASP CRSImplemented
Cloudflare edge allowlistOne-click
cPHulk, Apache, LiteSpeed, EximDetected
Availability

Download CSF 2.1.5 - stable.

2.1.5 is the current stable release, free and open source under the GNU GPL v3. It installs the native nftables engine, LFD 2.0, cPanel integration, Threat Intelligence, the Cloudflare edge allowlist, WAF escalation, and the WHM interface - and cleanly migrates and uninstalls both legacy ConfigServer CSF v15 and the cPanel-maintained CSF fork. Available to every cPanel server and rolled out across UnderHost infrastructure as part of UnderShield.

UnderShield™Protection and monitoring, built into UnderHost infrastructure.
ProductCSF 2.1
Build2.1.5
Channelstable
Released2026-08-26
Upgrades fromCSF 15 · cPanel CSF
LicenseGPL-3.0
PriceFree
FAQ

Frequently asked questions

Everything administrators ask before switching their cPanel firewall.

Is CSF - cPanel Shield Firewall free and open source?
Yes. It is free and open source under the GNU GPL v3 - no license fee and no subscription.
Is this the same as ConfigServer Security & Firewall (CSF)?
It is an independent, next-generation fork of ConfigServer Security & Firewall, rebuilt on native nftables. It preserves the familiar csf commands and config files (csf.conf, csf.allow, csf.deny, csf.ignore) and adds an event-driven LFD 2.0, live Threat Intelligence, and an embedded WHM interface.
Can I upgrade from CSF v15 or the cPanel CSF fork?
Yes. The installer detects an existing ConfigServer CSF v15 install or the cPanel-maintained CSF fork, backs up and migrates your csf.conf, allow, deny and ignore files, then removes the old iptables-based install so no stale rules remain.
Which operating systems and control panels are supported?
cPanel & WHM on AlmaLinux, CloudLinux, RHEL and Rocky 8, 9 and 10 are supported; Ubuntu 22.04 / 24.04 LTS runs on the same nftables engine (community beta). A modern kernel with nftables is required.
Does it support nftables and IPv6?
Yes - a single native nftables inet table filters IPv4 and IPv6 together, with dynamic sets for CIDR ranges and timeout-based temporary bans.
Does it work with Cloudflare?
Yes. One click adds every Cloudflare edge IP range (IPv4 and IPv6) to the allow list, so visitor traffic proxied through Cloudflare is never blocked by LFD.
How do I install it?
Download the release, verify its SHA-256 checksum, and run install.sh as root. The installer migrates any legacy CSF, auto-detects your SSH and cPanel ports, and installs in TESTING mode until you enable enforcement. Full steps are in the documentation.