nftables-first architecture
A single table inet csf with dynamic, timeout-capable sets - IPv4 and IPv6 in one model. Blocking one IP updates a set element, never a rebuild.
StableA cPanel-first firewall built on native nftables, IPv4 + IPv6, an event-driven LFD 2.0, and live Threat Intelligence - part of UnderShield. Version 2.1.5 stable is available now, free and open source.
2.1.5 is the current stable release - feature-complete, unit-tested, and validated on live cPanel servers. GPL-3.0.
# csf -d 185.203.44.19 SSH brute force csf: 185.203.44.19 added to csf_deny4 (nft set - no rebuild) # csf inspect 185.203.44.19 state ...... BLOCKED set .... csf_deny4 # csf health nft table ok · sets ok · ruleset validated build: 2.1.5 (stable)
Every capability below ships in the 2.1.5 stable release, backed by a 460+ assertion automated test suite and validated on live cPanel servers.
A single table inet csf with dynamic, timeout-capable sets - IPv4 and IPv6 in one model. Blocking one IP updates a set element, never a rebuild.
StableAn event-driven detection layer with modular collectors, incremental log tailing, temporary blocks with native set timeouts, and a clear reason behind every action.
StableService and version detection, cPHulk and ModSecurity awareness, automatic SSH/cPanel port presets on install, and a WHM interface registered through AppConfig.
StableReputable IP/CIDR feeds (Spamhaus DROP, Feodo C2, CINS, IPsum, Blocklist.de) load into dedicated nftables sets with per-feed toggles and category policies - inbound, outbound, or both.
StableAtomic rule changes, a lockout guard that checks your live SSH session, and a --safe-reload watchdog that auto-reverts if you can't confirm.
StableThe WHM interface checks the release channel, then downloads, SHA-256 verifies, and installs new versions in place with a live progress bar - your config and lists preserved.
StableThe path a request takes through CSF 2.1 - traceable steps, explainable decisions, no opaque automation.
Suspicious activity reaches a protected service.
A log line records an actionable signal.
Collectors normalise it into a structured event.
The risk engine scores the source and checks thresholds.
The IP is added to a set with a timeout.
Traffic is dropped in-kernel before it reaches the service.
Modular collectors watch the parts of a cPanel server that matter most and feed a single correlation engine, so a distributed attacker is recognised as one hostile actor and enforced progressively.
service sshd event authentication_failure source 185.203.44.19 score 72 / short block action add to csf_temp4 (timeout 300s) reason LFD: sshd auth_failure (score 72)
# csf -a 203.0.113.7 # allow # csf -td 198.51.100.9 3600 # temporary deny # csf -g 198.51.100.9 # inspect # csf --safe-reload # apply, auto-revert # csf --self-update # update in place The familiar commands you know, on a native nftables engine. Legacy csf.conf is migrated.
Your operational muscle memory carries over. The familiar commands and configuration files drive a native nftables engine underneath.
CSF 2.1 runs on the modern Linux distributions cPanel & WHM support, with first-class nftables on EL8/9/10. Ubuntu is supported on the same nftables engine (community beta).
2.1.5 is the current stable release, free and open source under the GNU GPL v3. It installs the native nftables engine, LFD 2.0, cPanel integration, Threat Intelligence, the Cloudflare edge allowlist, WAF escalation, and the WHM interface - and cleanly migrates and uninstalls both legacy ConfigServer CSF v15 and the cPanel-maintained CSF fork. Available to every cPanel server and rolled out across UnderHost infrastructure as part of UnderShield.
Everything administrators ask before switching their cPanel firewall.