CSF - Config Server Firewall
ConfigServer Firewall (csf)
The mains scripts provided by the csf are:
# Straight-forward SPI (Stateful Packet Inspection) iptables firewall script.
# Daemon process that checks for login authentication failures for:
* courier imap and pop3
* ssh
* non-ssl cpanel / whm / webmail (cPanel servers only)
* pure-pftd
* password protected web pages (htpasswd)
* mod_security failures
# POP3/IMAP login tracking to enforce logins per hour
# SSH login notification
# Excessive connection blocking
# WHM iptables report log (cPanel servers only)
# Block traffic on unused server IP addresses - helps reduce the risk to your server
# Alert when end-user scripts sending excessive emails per hour - for identifying spamming scripts
# Suspicious process reporting - reports potential exploits running on the server
# Excessive user processes reporting
# Suspicious file reporting - reports potential exploit files in /tmp and similar directories
# Directory and file watching - reports if a watched directory or a file changes
# Server Security Check - Performs a basic security and settings check on the server (cPanel servers only)
# Alert sent if server load average remains high for a specified length of time
# mod_security log reporting (if installed)
