ConfigServer Security & Firewall (CSF) is a suite of scripts provides:
- A straight-forward SPI iptables firewall script;
- A daemon process that checks for Login Authentication;
- A Control Panel configuration interface;
- ... and much more!
The tutorial was prepared with our "CentOS 7 + DirectAdmin" template and is meant to work on our self-managed virtual private servers.
0. Preliminary requirements:- "CentOS 7 + DirectAdmin" template installed on server;
- Fully updates server software (yum update).
1. CSF installationInstallation of CSF is quite straightforward because it preconfigured to work with DirectAdmin:
cd /usr/src
wget https://download.configserver.com/csf.tgz
tar -xzf csf.tgz
cd csf
sh install.sh
2. CSF configurationAfter installation CSF starts in testing mode and there are a couple of things to take care of. First of all, you have to log in to your DirectAdmin. By default, the address is:
http://your-server-ip:2222After successfully login you should select "ConfigServer Firewall&Security":
data:image/s3,"s3://crabby-images/9dfc5/9dfc5daf061a7bb6191caeaa7e09622a07f6c1b6" alt="Image: https://images.time4vps.com/images/2020/02/25/6c463a9e22ccc07872ca12a1ebf99913.png"
You should now see that there are two notices that we need to take care of. So select "ConfigServer Firewall" and then select "Firewall Configuration":
data:image/s3,"s3://crabby-images/89098/890987e2d6f309d89164f77b22527c457fdfca75" alt="Image: https://images.time4vps.com/images/2020/02/25/acdf5f0e17d17aba5922e7826d8d874f.png"
First, we will turn off testing mode:
data:image/s3,"s3://crabby-images/9e210/9e2103d7bed4459e9104b49ab5aaf20bcc97f04a" alt="Image: https://community.time4vps.com/uploads/editor/li/8mx6rlx0638b.png"
And then we should restrict syslog/rsyslog access:
data:image/s3,"s3://crabby-images/a19e5/a19e55e0507571b2f3d019462d4147cba6f10531" alt="Image: https://community.time4vps.com/uploads/editor/p9/pg5coy3i1for.png"
After these changes press the button "Change" at the bottom of the page and "Restart csf+lfd" afterward.
That is it, now you have a fully working ConfigServer firewall. For more information regarding CSF please visit their
Read me page.
Comments
Installing ConfigServer Security & Firewall (CSF) on DirectAdmin is a prudent move to bolster server security. CSF provides a robust defense mechanism against threats, offering features like IP blocking and connection tracking. Its integration with DirectAdmin streamlines management, ensuring a comprehensive and user-friendly approach to safeguarding your server environment.
thank you so much good informetion