---
title: CSF
url: 'https://docs.danami.com/juggernaut/command-line-interface/csf'
markdown: 'https://docs.danami.com/juggernaut/command-line-interface/csf.md'
date: '2026-10-07'
description: 'This manual documents the csf command line options for the ConfigServer & Security Firewall. See /etc/csf/csf.conf and /etc/csf/readme.txt for more detailed information on how to use and configure this application. csf --help Option Description --help Show this message --status List/Sh…'
taxonomy:
  category:
    - docs
  tag:
    - csf
---

[](#)  [ Basics ](https://docs.danami.com/juggernaut/)     [ Command Line Interface ](https://docs.danami.com/juggernaut/command-line-interface)      CSF    

# CSF

This manual documents the csf command line options for the ConfigServer & Security Firewall. See `/etc/csf/csf.conf` and `/etc/csf/readme.txt` for more detailed information on how to use and configure this application.

```
csf --help
```

| Option | Description |
|---|---|
| `--help` | Show this message |
| `--status` | List/Show the IPv4 iptables configuration |
| `--status6` | List/Show the IPv6 ip6tables configuration |
| `--start` | Start the firewall rules |
| `--stop` | Flush/Stop firewall rules (Note: lfd may restart csf) |
| `--restart` | Restart firewall rules (csf) |
| `--startq` | Quick restart (csf restarted by lfd) |
| `--startf` | Force CLI restart regardless of LFDSTART setting |
| `--restartall` | Restart firewall rules (csf) and then restart lfd daemon. Both csf and then lfd should be restarted after making any changes to the configuration files |
| `--lfd [stop\|start\|restart\|status]` | Actions to take with the lfd daemon |
| `--add ip [comment]` | Allow an IP and add to /etc/csf/csf.allow |
| `--addrm ip` | Remove an IP from /etc/csf/csf.allow and delete rule |
| `--deny ip [comment]` | Deny an IP and add to /etc/csf/csf.deny |
| `--denyrm ip` | Unblock an IP and remove from /etc/csf/csf.deny |
| `--denyf` | Remove and unblock all entries in /etc/csf/csf.deny |
| `--grep ip` | Search the iptables and ip6tables rules for a match (e.g. IP, CIDR, Port Number) |
| `--iplookup ip` | Lookup IP address geographical information using CC\_LOOKUPS setting in /etc/csf/csf.conf |
| `--temp` | Displays the current list of temporary allow and deny IP entries with their TTL and comment |
| `--temprm ip` | Remove an IP from the temporary IP ban or allow list |
| `--temprmd ip` | Remove an IP from the temporary IP ban list only |
| `--temprma ip` | Remove an IP from the temporary IP allow list only |
| `--tempdeny ip ttl [-p port] [-d direction] [comment]` | Add an IP to the temp IP ban list. ttl is how long to blocks for (default:seconds, can use one suffix of h/m/d). Optional port. Optional direction of block can be one of: in, out or inout (default:in) |
| `--tempallow ip ttl [-p port] [-d direction] [comment]` | Add an IP to the temp IP allow list (default:inout) |
| `--tempf` | Flush all IPs from the temporary IP entries |
| `--cping` | PING all members in an lfd Cluster |
| `--cgrep ip` | Requests the --grep output for IP from each member in an lfd Cluster |
| `--cdeny ip [comment]` | Deny an IP in a Cluster and add to each remote /etc/csf/csf.deny |
| `--ctempdeny ip ttl [-p port] [-d direction] [comment]` | Add an IP in a Cluster to the temp IP ban list (default:in) |
| `--crm ip` | Unblock an IP in a Cluster and remove from each remote /etc/csf/csf.deny and temporary list |
| `--callow ip [comment]` | Allow an IP in a Cluster and add to each remote /etc/csf/csf.allow |
| `--ctempallow ip ttl [-p port] [-d direction] [comment]` | Add an IP in a Cluster to the temp IP allow list (default:in) |
| `--carm ip` | Remove allowed IP in a Cluster and remove from each remote /etc/csf/csf.allow and temporary list |
| `--cignore ip [comment]` | Ignore an IP in a Cluster and add to each remote /etc/csf/csf.ignore. Note: This will result in lfd being restarted |
| `--cirm ip` | Remove ignored IP in a Cluster and remove from each remote /etc/csf/csf.ignore. Note: This will result in lfd being restarted |
| `--cconfig [name] [value]` | Change configuration option \[name\] to \[value\] in a Cluster |
| `--cfile [file]` | Send \[file\] in a Cluster to /etc/csf/ |
| `--crestart` | Cluster restart csf and lfd |
| `--trace [add\|remove] ip` | Log SYN packets for an IP across iptables chains. Note, this can create a LOT of logging information in /var/log/messages so should only be used for a short period of time. This option requires the iptables TRACE module and access to the raw PREROUTING chain to function |
| `--mail [email]` | Display Server Check in HTML or email to \[email\] if present |
| `--rbl [email]` | Process and display RBL Check in HTML or email to \[email\] if present |
| `--logrun` | Initiate Log Scanner report via lfd |
| `--ports` | View ports on the server that have a running process behind them listening for external connections |
| `--graphs [graph type] [directory]` | Generate System Statistics html pages and images for a given graph type into a given directory. See ST\_SYSTEM for requirements |
| `--profile [command] [profile\|backup] [profile\|backup]` | Configuration profile functions for /etc/csf/csf.conf. You can create your own profiles using the examples provided in /usr/local/csf/profiles/. The profile reset\_to\_defaults.conf is a special case and will always be the latest default csf.conf |
| `--mregen` | MESSENGERV2 /etc/apache2/conf.d/csf\_messenger.conf regeneration. This will also gracefully restart httpd |
| `--cloudflare [command]` | Commands for interacting with the CloudFlare firewall. See /etc/csf/readme.txt and CF\_ENABLE for more detailed information |
| `--check` | Check for updates to csf but do not upgrade |
| `--update` | Check for updates to csf and upgrade if available |
| `-uf` | Force an update of csf whether and upgrade is required or not |
| `--disable` | Disable csf and lfd completely |
| `--enable` | Enable csf and lfd if previously disabled |
| `--version` | Show csf version |

## Profile commands

| Command | Description |
|---|---|
| `list` | Lists available profiles and backups |
| `apply [profile]` | Modify csf.conf with Configuration Profile |
| `backup "name"` | Create Configuration Backup with optional "name" stored in /var/lib/csf/backup/ |
| `restore [backup]` | Restore a Configuration Backup |
| `keep [num]` | Remove old Configuration Backups and keep the latest \[num\] |
| `diff [profile\|backup] [profile\|backup]` | Report differences between Configuration Profiles or Configuration Backups, only specify one \[profile\|backup\] to compare to the current Configuration |

## Cloudflare commands

Note: target can be one of: An IP address; 2 letter Country Code; IP range CIDR. Only Enterprise customers can block a Country Code, but all can allow and challenge. IP range CIDR is limited to /16 and /24

| Command | Description |
|---|---|
| `list [all\|block\|challenge\|whitelist] [user1,user2,domain1...]` | List specified type of CloudFlare Firewall rules for comma separated list of users/domains |
| `add [block\|challenge\|whitelist] target [user1,user2,domain1...]` | Add CloudFlare Firewall rule action for target for comma separated list of users/domains only |
| `del target [user1,user2,domain1...]` | Delete CloudFlare Firewall rule for target for comma separated list of users/domains only |
| `tempadd [allow\|deny] ip [user1,user2,domain1...]` | Add a temporary block for CF\_TEMP seconds to both csf and the CloudFlare Firewall rule for ip for comma separated list of users/domains as well as any user set to "any" |

## Files

| File | Description |
|---|---|
| `/etc/csf/csf.conf` | The system wide configuration file |
| `/etc/csf/readme.txt` | Detailed information about csf and lfd |

## Examples

```
// permanently deny an attacking IP with a comment for future reference
csf --deny 203.0.113.66 attacker

// temporarily block an IP for 2 hours on incoming SSH only
csf --tempdeny 203.0.113.99 2h -p 22 -d in ssh-brute

// allow a VPN subnet so it is never blocked by the login failure daemon
csf --add 192.168.254.0/24 vpn

// look up the geographical information for an IP before blocking it
csf --iplookup 203.0.113.66

// restart csf and lfd after making changes to the configuration files
csf --restartall
```

## Related Pages

- [Watching IP Addresses](https://docs.danami.com/juggernaut/user-guide/watching-ip-addresses "Watching IP Addresses")
- [External Pre and Post Scripts](https://docs.danami.com/juggernaut/user-guide/external-pre-and-post-scripts "External Pre and Post Scripts")
- [Firewall](https://docs.danami.com/juggernaut/user-guide/firewall "Firewall")
- [Port / IP Redirection](https://docs.danami.com/juggernaut/user-guide/port-ip-redirection "Port / IP Redirection")
- [Disable Server IP Addresses](https://docs.danami.com/juggernaut/user-guide/disable-server-ip-addresses "Disable Server IP Addresses")

 [ ](https://docs.danami.com/juggernaut/user-guide/disable-server-ip-addresses) [](https://docs.danami.com/juggernaut/command-line-interface/firewall/firewall-disableserverips)

---

## Navigation

- Parent: [Command Line Interface](https://docs.danami.com/juggernaut/command-line-interface.md)
