---
title: 'firewall:port'
url: 'https://docs.danami.com/juggernaut/command-line-interface/firewall/firewall-port'
markdown: 'https://docs.danami.com/juggernaut/command-line-interface/firewall/firewall-port.md'
date: '2026-10-07'
description: 'Configure incoming and outgoing port settings. juggernaut --task=firewall:port Option Value Default Description --LF_SPI <1|0> 1 Some kernel/iptables setups do not perform stateful connection tracking correctly (typically some virtual servers or custom compiled kernels) , so an SP…'
taxonomy:
  category:
    - docs
  tag:
    - ports
---

[](#)  [ Basics ](https://docs.danami.com/juggernaut/)     [ Command Line Interface ](https://docs.danami.com/juggernaut/command-line-interface)      Firewall       firewall:port    

# firewall:port

Configure incoming and outgoing port settings.

```
juggernaut --task=firewall:port
```

| Option | Value | Default | Description |
|---|---|---|---|
| `--LF_SPI` | <1\|0> | 1 | Some kernel/iptables setups do not perform stateful connection tracking correctly (typically some virtual servers or custom compiled kernels) , so an SPI firewall will not function correctly. If this happens, LF\_SPI can be set to 0 to reconfigure csf as a static firewall. As connection tracking will not be configured, applications that rely on it will not function unless all outgoing ports are opened. Therefore, all outgoing connections will be allowed once all other tests have completed. So TCP\_OUT, UDP\_OUT and ICMP\_OUT will not have any effect. |
| `--TCP_IN` | <string1,string2> | 20,21,22,25,53,80,110,143,443,465,587,853,993,995,8443,8447,8880,30000:35000 | Allow incoming TCP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--TCP_IN_add` | <string> |  | Add a single entry to TCP\_IN. |
| `--TCP_IN_del` | <string> |  | Remove a single entry from TCP\_IN. |
| `--TCP_OUT` | <string1,string2> | 20,21,22,25,43,53,80,110,113,143,443,465,587,853,873,993,995,2703,5224,8443,8447,8880 | Allow outgoing TCP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--TCP_OUT_add` | <string> |  | Add a single entry to TCP\_OUT. |
| `--TCP_OUT_del` | <string> |  | Remove a single entry from TCP\_OUT. |
| `--UDP_IN` | <string1,string2> | 20,21,53,80,443,8443,24441 | Allow incoming UDP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--UDP_IN_add` | <string> |  | Add a single entry to UDP\_IN. |
| `--UDP_IN_del` | <string> |  | Remove a single entry from UDP\_IN. |
| `--UDP_OUT` | <string1,string2> | 20,21,53,113,123,443,873,6277,8443,24441,33434:33523 | Allow outgoing UDP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). To allow outgoing traceroute add 33434:33523 to this list. |
| `--UDP_OUT_add` | <string> |  | Add a single entry to UDP\_OUT. |
| `--UDP_OUT_del` | <string> |  | Remove a single entry from UDP\_OUT. |
| `--ICMP_IN` | <1\|0> | 1 | Allow incoming PING. |
| `--ICMP_IN_RATE` | <string> | 1/s | Set the incoming ICMP packet rate per IP address. To disable this option set to 0. |
| `--ICMP_OUT` | <1\|0> | 1 | Allow outgoing PING. |
| `--ICMP_OUT_RATE` | <string> | 0 | Set the outgoing ICMP packet rate per IP address. To disable this option set to 0. |
| `--ICMP_TIMESTAMPDROP` | <1\|0> | 0 | For those with PCI Compliance tools that state that ICMP timestamps (type 13) should be dropped, you can enable the following option. Otherwise, there appears to be little evidence that it has anything to do with a security risk and can impact network performance, so should be left disabled by everyone else. |
| `--IPV6` | <1\|0> | 1 | Enable or disable IPV6 support. |
| `--IPV6_ICMP_STRICT` | <1\|0> | 0 | IPv6 uses icmpv6 packets very heavily. By default, csf will allow all icmpv6 traffic in the INPUT and OUTPUT chains. However, this could increase the risk of icmpv6 attacks. To restrict incoming icmpv6, set to 1 but may break some connection types. |
| `--IPV6_SPI` | <1\|0> | 1 | Enable or disable IPV6 stateful packet inspection. Do not enable on pre v2.6.20 kernels as they do not perform stateful connection tracking. |
| `--TCP6_IN` | <string1,string2> | 20,21,22,25,53,80,110,143,443,465,587,853,993,995,8443,8447,8880,30000:35000 | Allow incoming IPv6 TCP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--TCP6_IN_add` | <string> |  | Add a single entry to TCP6\_IN. |
| `--TCP6_IN_del` | <string> |  | Remove a single entry from TCP6\_IN. |
| `--TCP6_OUT` | <string1,string2> | 20,21,22,25,43,53,80,110,113,143,443,465,587,853,873,993,995,2703,5224,8443,8447,8880 | Allow outgoing IPv6 TCP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--TCP6_OUT_add` | <string> |  | Add a single entry to TCP6\_OUT. |
| `--TCP6_OUT_del` | <string> |  | Remove a single entry from TCP6\_OUT. |
| `--UDP6_IN` | <string1,string2> | 20,21,53,80,443,8443,24441 | Allow incoming IPv6 UDP ports (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). |
| `--UDP6_IN_add` | <string> |  | Add a single entry to UDP6\_IN. |
| `--UDP6_IN_del` | <string> |  | Remove a single entry from UDP6\_IN. |
| `--UDP6_OUT` | <string1,string2> | 20,21,53,113,123,443,873,6277,8443,24441,33434:33523 | Allow outgoing IPv6 UDP ports. (comma separated). Port ranges can be specified using a colon. (e.g. 30000:35000). To allow outgoing traceroute add 33434:33523 to this list. |
| `--UDP6_OUT_add` | <string> |  | Add a single entry to UDP6\_OUT. |
| `--UDP6_OUT_del` | <string> |  | Remove a single entry from UDP6\_OUT. |
| `--default` | <yes> |  | Reset all settings to their default values. |
| `--default_option` | <option> |  | Reset a specific setting to its default value. |
| `--restart` | <yes> |  | Restart the service after saving settings. |

## Examples

```
// add port 6698 to TCP_IN
juggernaut --task=firewall:port --TCP_IN_add=6698 --restart=yes

// reset TCP_IN back to default
juggernaut --task=firewall:port --default_option=TCP_IN --restart=yes

// reset all settings back to default
juggernaut --task=firewall:port --default=yes --restart=yes

// open the XMPP port range for a Jabber server and restart the firewall
juggernaut --task=firewall:port --TCP_IN_add=5222:5223 --restart=yes

// stop answering incoming ping while leaving outgoing ping enabled
juggernaut --task=firewall:port --ICMP_IN=0 --ICMP_OUT=1 --restart=yes
```

## Related Pages

- [Port Settings](https://docs.danami.com/juggernaut/settings/other/port-settings "Port Settings")
- [Port Settings](https://docs.danami.com/juggernaut/settings/firewall/port-settings "Port Settings")
- [Plesk Firewall Port Numbers](https://docs.danami.com/juggernaut/misc/plesk-firewall-port-numbers "Plesk Firewall Port Numbers")

 [](https://docs.danami.com/juggernaut/command-line-interface/other/other-port)

---

## Navigation

- Previous: [firewall:logging](https://docs.danami.com/juggernaut/command-line-interface/firewall/firewall-logging.md)
- Next: [firewall:portflood](https://docs.danami.com/juggernaut/command-line-interface/firewall/firewall-portflood.md)
