ConfigServer Security & Firewall (CSF) & LFD Hardening: Stopping Brute-Force Attacks on Linux in Pakistan

A comprehensive guide to configuring ConfigServer Security & Firewall (CSF) and Login Failure Daemon (LFD). Stop SSH, cPanel, and SMTP brute-force attacks on Pakistani hosting servers.

ConfigServer Security & Firewall (CSF) & LFD Hardening: Stopping Brute-Force Attacks on Linux in Pakistan

The moment a public IPv4 address is assigned to a production Linux server in Pakistan, automated botnets begin hammering its standard ports. Within hours of deployment, /var/log/secure or /var/log/auth.log records thousands of failed authentication attempts against SSH (port 22), cPanel (port 2083), WHM (port 2087), and Exim SMTP (port 25).

If unmitigated, these relentless dictionary attacks not only risk credential compromise but also saturate CPU cycles through repetitive cryptographic hashing (PAM / bcrypt / SHA-512).

For system administrators managing enterprise servers, cPanel nodes, or independent virtual machines, ConfigServer Security & Firewall (CSF) paired with the Login Failure Daemon (LFD) is the gold standard host-level security suite.

This technical guide demonstrates how to install CSF/LFD, fine-tune intrusion detection thresholds, configure temporary vs. permanent IP bans, and implement port knocking on enterprise Dedicated Servers in Pakistan.


Understanding the Architecture: CSF vs. LFD

CSF and LFD are not separate firewall engines; they are an orchestrated security stack built directly on top of Linux kernel iptables and ipset:

[Incoming Connection: SSH / cPanel / SMTP]
                     │
                     ▼
          [CSF Firewall (iptables / ipset)]
                     ├── Matches Whitelist (csf.allow)? ──► PERMIT
                     ├── Matches Blacklist (csf.deny)?  ──► DROP
                     │
                     ▼ Allowed through to application
            [Application Authentication]
          (OpenSSH / cPanel / Dovecot / Exim)
                     │
                     ▼ If login fails: Writes to /var/log/secure
           [LFD (Login Failure Daemon)]
                     │
                     ├── Monitors log streams in real-time via inotify
                     ├── Counts failure attempts per source IP
                     │
                     ▼ Threshold Exceeded? (e.g. 5 failures in 300s)
            [LFD triggers CSF iptables DROP!]
          (Attacker IP is blacklisted in kernel memory!)
  1. CSF (Stateful Packet Filter): Manages open incoming/outgoing ports, SYN flood protection, ping request rate limits, and custom routing tables.
  2. LFD (Intrusion Detection Daemon): Continuously tails authentication log files. When a specific IP address exceeds failed login thresholds across any service, LFD automatically invokes CSF to blacklist the offending IP at the kernel network level.

Step-by-Step Installation on Modern Linux (AlmaLinux / Rocky / Debian / Ubuntu)

1. Installing Prerequisites and CSF

# On RHEL / AlmaLinux / Rocky Linux:
dnf install -y perl perl-libwww-perl ipset bind-utils

# Download and extract the official CSF package
cd /usr/src
wget https://download.configserver.com/csf.tgz
tar -xzf csf.tgz
cd csf
sh install.sh

# Verify that all required kernel iptables modules are supported
perl /usr/local/csf/bin/csftest.pl
# Expected result: "RESULT: csf should work on this server"

Critical Configuration: Tuning /etc/csf/csf.conf

Before starting the firewall, you must tune /etc/csf/csf.conf and disable Testing Mode.

1. Disabling Testing Mode

By default, CSF ships in testing mode (TESTING = "1"), which clears all iptables rules every 5 minutes via cron to prevent accidental administrator lockouts.

# /etc/csf/csf.conf
TESTING = "0"

2. Locking Down Inbound and Outbound Ports

Explicitly restrict open ports to only the services you actively operate:

# Inbound TCP Ports (Example for a hardened cPanel/Web server)
TCP_IN = "20,21,22,25,53,80,110,143,443,465,587,993,995,2077,2078,2082,2083,2086,2087"

# Outbound TCP Ports (Restrict outgoing connections to stop reverse shells)
TCP_OUT = "20,21,22,25,53,80,113,443,587,993,2087"

# Inbound UDP Ports (DNS & NTP)
UDP_IN = "53"
UDP_OUT = "53,113,123"

3. Accelerating IP Lookups with ipset

In high-density server environments where thousands of botnet IPs are blocked daily, standard linear iptables chains cause noticeable CPU overhead. Enabling ipset switches lookups to high-speed $O(1)$ memory hash tables:

# Enable ipset for million-IP blacklists with zero latency
LF_IPSET = "1"

Tuning LFD Brute-Force Thresholds

LFD allows setting precise failure limits per service:

# SSH Brute-Force Trigger (5 failed attempts within 300 seconds)
LF_SSHD = "5"
LF_SSHD_PERM = "3600" # Temporary ban for 1 hour (Set to 1 for permanent ban)

# cPanel & WHM Login Failures
LF_CPANEL = "5"
LF_CPANEL_PERM = "3600"

# IMAP / POP3 Dovecot Failures
LF_POP3D = "10"
LF_POP3D_PERM = "1800"

# Exim SMTP Authentication Failures
LF_SMTPAUTH = "5"
LF_SMTPAUTH_PERM = "3600"

# Directory Traversal & Suspicious File Access
LF_DIRWATCH = "300"
LF_INTEGRITY = "3600"

Managing Bans from the Linux CLI

CSF provides an intuitive, high-speed command-line interface for day-to-day operations:

# Whitelist a trusted office IP permanently
csf -a 103.151.43.50 "Islamabad Head Office"

# Blacklist a malicious attacker IP permanently
csf -d 198.51.100.22 "Malicious WordPress Scanner"

# Temporarily ban an IP for 2 hours (7200 seconds)
csf -td 198.51.100.22 7200 "DDoS burst"

# Search active iptables rules to see why an IP was blocked
csf -g 198.51.100.22

# Unblock an accidentally banned client IP
csf -dr 198.51.100.22
csf -tr 198.51.100.22

# Reload the firewall configuration cleanly
csf -r

Hardening against SYN Floods & Connection Starvation

CSF includes built-in Layer-4 connection rate limiting to blunt SYN floods and connection exhaustion attacks:

# Enable SYN Flood Protection
SYNFLOOD = "1"
SYNFLOOD_RATE = "100/s"
SYNFLOOD_BURST = "150"

# Limit maximum concurrent connections per IP on port 80/443
CONNLIMIT = "80;50,443;50" # Max 50 concurrent connections per IP on web ports

If an attacker tries to open 500 parallel TCP connections to exhaust your web server’s worker threads, CSF automatically terminates the excess connections at the kernel boundary!


Bare-Metal Isolation for High-Security Infrastructure

While CSF/LFD provides world-class host-level intrusion prevention, virtualized VPS environments share hypervisor network buffers and CPU schedulers. Under a massive volumetric attack, a VPS firewall can be overwhelmed before packets ever hit user space.

Deploying on dedicated bare-metal infrastructure ensures that your firewalls operate with unshared multi-gigabit hardware uplinks, hardware IPMI out-of-band recovery, and dedicated CPU processing power.

Explore Nextgen’s high-performance bare-metal Dedicated Servers and locally hosted Dedicated Servers in Pakistan.

Secure Your Production Fleets with Nextgen

Protect your servers from unauthorized intrusions, brute-force bots, and DDoS floods. Deploy enterprise Linux servers on dedicated bare-metal hardware backed by our 4.7/5 Trustpilot rated support in Pakistan.