On reboot, my home IP address is blocked until firewall restarted

Running AlmaLinux v8.10.0 STANDARD kvm on a VPS. CPanel version 130.0.3

A new problem popped up in the past month.

At some time in the past, my home IP address got blocked for too many failed logins (from Apple Mail retrying multiple email addresses). I used csf (v14.24) to unblock and whitelist the IP address. That worked fine for a long time. Then out of the blue (or at least I am not aware of any change I made that would cause it) when I rebooted the VPS, my IP address was again locked out of http access on all my websites. I was able to use a VPN to log back into WHM and restart the firewall using csf and then I could access my websites and WHM again from my home IP–the whitelist was in effect again after restarting the firewall. Ever since, every time I reboot, I have to restart the firewall to activate the whitelist to let my home IP address back in.

My home IP is not static and is through xfinity, so a VPN is the only way I can change my IP address. Rebooting the router doesn’t change the home IP address.

It seems as if there is a conflict happening where the whitelist from csf isn’t loading on reboot, or it’s loading and then something else loads after and clobbers it. Are there conflicting rules somewhere? Is something loading in the wrong order? Do I have two competing firewalls running?

One thing I noticed is that the /etc/firewalld/firewalld.conf has FirewallBackend=nftables, but in csf it talks only about iptables. Is csf just a frontend for firewalld? In which case could that be the source of the conflict?

I had a lot of *nix experience decades ago, so I’m familiar with the basics, but I’m not current on how firewalls work. I’m not sure where to start to troubleshoot this.

Thanks in advance for any help.

hi

There is a high possibility that the issue is caused by a conflict between firewalld and CSF (ConfigServer Security & Firewall).

First, please check the status of both services using the systemctl command:

systemctl status firewalld
systemctl status csf

If both are shown as “active (running)”, then a conflict is occurring. In that case, it is recommended to have only one of them enabled.
Normally, it is common to disable firewalld and use only CSF for firewall management:

sudo systemctl disable --now firewalld
sudo systemctl enable --now csf

This should ensure that the CSF whitelist is properly applied even after a reboot.

Good luck

Disabling the firewalld will be the greatest risk that should be avoided at all cost.

Instead, Login to your server and enter:

iptables -F

Do you really need CSF when firewalld is active?