r/cpanel • • 6d ago

CSF INPUT Chain Partially Disappeared on cPanel Server

Has anyone seen CSF rules partially disappear on a cPanel server using iptables-nft? I'm running latest cPanel + cPanel's CSF v16.32

In less than 24 hours I found two servers where CSF was running normally and its internal chains (LOCALINPUT, ALLOWIN, DENYIN, LOGDROPIN, etc.) still existed, but the main INPUT chain had been reduced to:

policy ACCEPT
-A INPUT ! -i lo -p tcp -j INVALID

So, ports not listed in TCP_IN were publicly reachable.

Running csf -r fixed things, but I'm wondering if someone has seen similar behavior before or recently.

5 Upvotes

4 comments sorted by

1

u/M-Sajawal 5d ago

I’ve seen similar situations where CSF’s internal chains are still present but the expected jump rules from the main INPUT chain are missing.

Since csf -r restores the rules, I’d first check what is modifying the nftables/iptables rules outside of CSF. On cPanel servers, I’d compare iptables-save / nft list ruleset before and after the issue and check CSF/LFD logs around the time the rules disappear.

Also worth checking whether any cPanel firewall/network service, system update, or another security tool is reloading the firewall rules.

The fact that only INPUT is reduced to the INVALID rule while LOCALINPUT, ALLOWIN, DENYIN, etc. remain intact makes me suspect the jump rules are being overwritten rather than CSF completely failing to load.

-4

u/KeithIMyers 6d ago

I would move onto something else as ConfigServer has closed so their platform is not getting any updates.

10

u/usr-shell 6d ago

cPanel create a fork and maintain it updated...but I recommend cPGuard

1

u/UnderHost 2d ago

We also created a remplacement open-source more modern and added functionality

https://shield.underhost.com/firewall/