Control Web Panel

Security => CSF Firewall => Topic started by: setecabanas on October 14, 2025, 03:07:58 PM

Title: Firewall off in cwp panel
Post by: setecabanas on October 14, 2025, 03:07:58 PM
firewall appears disabled in cwp panel

but csf is working correctly

[root@s3 services]# csf -e
csf and lfd are not disabled!

[root@s3 services]# csf -e
csf and lfd are not disabled!


any idea?
Title: Re: Firewall off in cwp panel
Post by: overseer on October 14, 2025, 03:49:34 PM
Try toggling it on/off/on in the web GUI -- sometimes it gets out of sync with the actual CSF reality (a bug).
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 14, 2025, 04:46:12 PM
Yes thanks, I had already tried that but nothing.
Title: Re: Firewall off in cwp panel
Post by: Starburst on October 14, 2025, 05:50:55 PM
SSH into the server, and from the CLI:

csf -e, if working you should see what you are "csf and lfd are not disabled!"
That's a good thing.

Then run:

Code: [Select]
systemctl start csf
Code: [Select]
systemctl start lfd
Code: [Select]
systemctl enable csf
Code: [Select]
systemctl enable lfd
Some system are weird.

Log back into CWP, and it should show as 'On' now.
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 15, 2025, 08:29:49 AM
thanks
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 15, 2025, 02:47:09 PM
I have tried to install a new server with Almalinux 9
So, in a fresh installation same problem. But it is not important, only affects cwp panel

Code: [Select]
[root@s3 almalinux]# csf -e
csf and lfd are not disabled!
[root@s3 almalinux]#
[root@s3 almalinux]#
[root@s3 almalinux]# systemctl start csf
[root@s3 almalinux]# systemctl start lfd
[root@s3 almalinux]# systemctl enable csf
[root@s3 almalinux]# systemctl enable lfd
Title: Re: Firewall off in cwp panel
Post by: overseer on October 15, 2025, 05:50:59 PM
And you've rebooted? Sometimes it takes a full reboot to get itself sorted out! :P
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 16, 2025, 11:10:44 AM
No, I had already restarted several times :D

I have no idea what's going on.
Do you know what the CWP checks to make it appear as activated?
Title: Re: Firewall off in cwp panel
Post by: overseer on October 16, 2025, 11:43:53 AM
It checks your IP address as registered in their system -- so your server connects to their licensing server to confirm that it is activated as CWP Pro.
Running /scripts/update_cwp will trigger the check daily.

And for good measure, here's their wiki article about CSF/LFD configuration:
https://wiki.centos-webpanel.com/csflfd-firewall-configuration
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 16, 2025, 04:33:44 PM
So, is very strange.

- lfd process is running

Code: [Select]
[root@s3 home]# ps -ef |grep lfd
root        1701       1  0 11:15 ?        00:00:26 lfd - sleeping

- cwp license pro is ok
- csf is enabled

However in cwp panel CSF is not enabled

i donīt know what happened :(
Title: Re: Firewall off in cwp panel
Post by: Starburst on October 16, 2025, 07:56:07 PM
What OS are you running on the server?
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 17, 2025, 06:59:28 AM
Distro Name: AlmaLinux release 9.6

[root@s3 csf]# csf -v
csf: v15.00 (CentOS Web Panel)
Title: Re: Firewall off in cwp panel
Post by: Starburst on October 18, 2025, 08:48:28 PM
That's what we run.

Usually once you start it & enable it via the CLI, and maybe reboot, CWP will see it running.

All CWP is doing in the background is running
Code: [Select]
systemctl status csfAnd then displaying On/Off
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 19, 2025, 05:49:57 AM
If it works for you, then I assume it's something specific to my server. But whatever. It's just a matter of ignoring the warning in CWP panel.

Code: [Select]
[root@s3 /]# systemctl status csf
● csf.service - ConfigServer Firewall & Security - csf
     Loaded: loaded (/usr/lib/systemd/system/csf.service; enabled; preset: disabled)
     Active: active (exited) since Sat 2025-10-18 11:51:50 UTC; 17h ago
   Main PID: 775 (code=exited, status=0/SUCCESS)
        CPU: 490ms

Oct 18 11:51:49 s3.domineando.eu systemd[1]: Starting ConfigServer Firewall & Security - csf...
Oct 18 11:51:50 s3.domineando.eu csf[775]: (restoring iptables) (restoring ip6tables)
Oct 18 11:51:50 s3.domineando.eu systemd[1]: Finished ConfigServer Firewall & Security - csf.
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 19, 2025, 08:29:50 AM
https://prnt.sc/i6_RvbeF1ytn
Title: Re: Firewall off in cwp panel
Post by: Starburst on October 20, 2025, 02:42:02 PM
Installing CWP on AL9 has a specific way.

Is this server in use by anything currently?

If not, you can reimage it with the Base AL9, and I could login and get everything setup for you.
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 21, 2025, 06:57:02 AM
I have installed CWP following these steps
https://forum.centos-webpanel.com/apache/issues-with-brand-new-fresh-install-with-almalinux-9-4/msg48375/#msg48375

Dont worry, I really appreciate your help but I assumed that is a problem to my server.
Thanks
Title: Re: Firewall off in cwp panel
Post by: Starburst on October 21, 2025, 05:10:57 PM
Defiantly try & run the line again
Code: [Select]
dnf install nano wget ipset ebtables iptables ipset-service uuid uuid-devel libuuid-develand make sure everything is installed.

If something was missing, CSF might not have installed correctly.
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 22, 2025, 05:35:42 AM
Code: [Select]
[root@s3 ]# dnf install nano wget ipset ebtables iptables ipset-service uuid uuid-devel libuuid-devel
Last metadata expiration check: 2:14:14 ago on Wed 22 Oct 2025 05:18:09 AM CEST.
Package nano-5.6.1-7.el9.x86_64 is already installed.
Package wget-1.21.1-8.el9_4.x86_64 is already installed.
Package ipset-7.11-11.el9_5.x86_64 is already installed.
Package iptables-nft-1.8.10-11.el9_5.x86_64 is already installed.
Package iptables-nft-1.8.10-11.el9_5.x86_64 is already installed.
Package ipset-service-7.11-11.el9_5.noarch is already installed.
Package uuid-1.6.2-55.el9.x86_64 is already installed.
Package uuid-devel-1.6.2-55.el9.x86_64 is already installed.
Package libuuid-devel-2.37.4-21.el9.x86_64 is already installed.
Dependencies resolved.
Nothing to do.
Complete!

In cpw panel firewall is OFF
csf works correctly in the server

maybe can try to uninstall csf and reinstall ...
Title: Re: Firewall off in cwp panel
Post by: setecabanas on October 22, 2025, 04:22:39 PM
Well, I think I have nothing else left to try

I have uninstall cwp and install again.
But everything same :(
Title: Re: Firewall off in cwp panel
Post by: overseer on October 22, 2025, 06:31:54 PM
If it's any comfort, it did this to me once -- and eventually just sorted itself out.
Title: Re: Firewall off in cwp panel
Post by: NIIcK on November 05, 2025, 12:23:00 PM
I had the same issue; it turned out that lfd was not starting because of an error "Unrecognized character \xE2" in /usr/local/csf/bin/regex.custom.pm lines 26 and 28.
You can check its status with: tail -f /var/log/lfd.log -> it seems that the csf -e command will only check if the services are enabled but will not report if they are actually running or not.

Basically all I needed to do was to change the “ ” to " " and lfd started again.

I hope it works for you.