Question
How do I configure DDoS mitigation in ConfigServer Firewall (CSF)?
Answer
Note: The cPanel technical support team cannot modify the firewall configuration on your behalf. If you require assistance making these changes, please consult with a qualified system administrator.
- Log in to WHM as the
rootuser. - Navigate to Home / Plugins / ConfigServer Security & Firewall.
- In the csf - ConfigServer Firewall section, click the Firewall Configuration button.
- Scroll down to the Connection Tracking section.
- Enter the desired value in the CT_LIMIT textbox.
- Set CT_EMAIL_ALERT to Off to avoid overloading the email server.
- Enter the ports being attacked in the CT_PORTS textbox.
- Scroll down to the Port Flood Settings section.
- Set SYNFLOOD to On.
- Enter the desired value in the SYNFLOOD_RATE textbox.
- Enter the desired value in the SYNFLOOD_BURST textbox.
- Scroll to the bottom of the page.
- Click the Change button.
- Click the Restart csf+lfd button.
Additional Resources
cPanel will provide its own fork of CSF starting Feb 25th, 2026
Comments
0 comments
Article is closed for comments.