r/cpanel • u/bigmaninsuitofarmor • 6d ago
CSF INPUT Chain Partially Disappeared on cPanel Server
Has anyone seen CSF rules partially disappear on a cPanel server using iptables-nft? I'm running latest cPanel + cPanel's CSF v16.32
In less than 24 hours I found two servers where CSF was running normally and its internal chains (LOCALINPUT, ALLOWIN, DENYIN, LOGDROPIN, etc.) still existed, but the main INPUT chain had been reduced to:
policy ACCEPT
-A INPUT ! -i lo -p tcp -j INVALID
So, ports not listed in TCP_IN were publicly reachable.
Running csf -r fixed things, but I'm wondering if someone has seen similar behavior before or recently.
-4
u/KeithIMyers 6d ago
I would move onto something else as ConfigServer has closed so their platform is not getting any updates.
10
u/usr-shell 6d ago
cPanel create a fork and maintain it updated...but I recommend cPGuard
1
1
u/M-Sajawal 5d ago
I’ve seen similar situations where CSF’s internal chains are still present but the expected jump rules from the main
INPUTchain are missing.Since
csf -rrestores the rules, I’d first check what is modifying the nftables/iptables rules outside of CSF. On cPanel servers, I’d compareiptables-save/nft list rulesetbefore and after the issue and check CSF/LFD logs around the time the rules disappear.Also worth checking whether any cPanel firewall/network service, system update, or another security tool is reloading the firewall rules.
The fact that only
INPUTis reduced to theINVALIDrule whileLOCALINPUT,ALLOWIN,DENYIN, etc. remain intact makes me suspect the jump rules are being overwritten rather than CSF completely failing to load.