How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (2023)

How to Configure Your Firewall for cPanel & WHM Services

Valid for versions 102 through 110

Version:

102

112

Last modified: April 6, 2023

Overview

cPanel & WHM installs and manages many different services on your system, most of which require an external connection in order to function properly. Because of this, your firewall must allow cPanel & WHM to open the ports on which these services run.

This document lists the ports that cPanel & WHM uses, and which services use each of these ports, to allow you to better configure your firewall.

Warning:

  • We strongly recommend that you only open ports for services that you use.
  • When you work with firewall rules, always make certain to include a way to log back in to your server, and always maintain console access to your server.

Ports

Warning:

We strongly recommend that you use the SSL version of each service whenever possible:

(Video) how to configure cpanel & whm | how to create a firewall rules on digital ocean

  • The use of non-SSL services can allow attackers to intercept sensitive information, such as login credentials.
  • Always ensure that valid SSL certificates exist for your services in WHM’s Manage Service SSL Certificates interface (WHM » Home » Service Configuration » Manage Service SSL Certificates).

Note:

For more information on how to access cPanel & WHM services, read our How to Log in to Your Server or Account documentation.

cPanel & WHM uses the following ports:

PortServiceTCPUDPInboundOutboundLocalhostNotes
1CPANHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (1)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (2)The Show Available Modules setting in cPanel’s Perl Modules interface (cPanel » Home » Software » Perl Modules) uses this port to improve the speed with which it appears.
7RazorHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (3)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (4)SpamAssassin uses the collaborative Razor spam-tracking database.
20FTPHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (5)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (6)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (7)Instead of FTP, we recommend that you use the more-secure SFTP service via SSH.
21FTPHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (8)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (9)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (10)Instead of FTP, we recommend that you use the more-secure SFTP service via SSH.
22SSHHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (11)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (12)You must open this port before you use WHM’s Transfer Tool interface (WHM » Home » Transfers » Transfer Tool) when:
  • You authenticate root users with SSH keys.
  • You are transferring from a server on cPanel & WHM version 88 or earlier.
25SMTPHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (13)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (14)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (15)
26SMTPHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (16)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (17)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (18)cPanel & WHM only uses this port if you specify it in WHM’s Service Manager interface (WHM » Home » Service Configuration » Service Manager).
37rdateHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (19)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (20)
43whoisHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (21)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (22)
53DNSHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (23)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (24)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (25)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (26)cPanel & WHM uses this port for the following functions:
  • Public DNS services.
  • Communication with root nameservers for AutoSSL.
  • Other functions that require name resolution.
80httpdHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (27)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (28)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (29)This port serves the HTTP needs of services on the server.

Important:

  • We strongly recommend that your users configure their websites on port 443, which uses the more secure SSL/TLS security protocol. For more information, read our More about TLS and SSL documentation.
  • The cPanel Server Daemon (cpsrvd) listens on this port when you disable the Web Server role. This daemon monitors cPanel & WHM services.
110POP3How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (30)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (31)
113identHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (32)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (33)
143IMAPHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (34)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (35)
443httpdHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (36)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (37)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (38)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (39)This port serves the HTTPS needs of services on the server.

Note:

  • This port can allow users to access cPanel or WHM via certain subdomains. For more information, read our Service and Proxy Subdomains documentation.
  • The cPanel Server Daemon (cpsrvd) listens on this port when you disable the Web Server role.
  • WHM’s Manage AutoSSL interface (WHM » Home » SSL/TLS » Manage AutoSSL) requires outbound access to the store.cpanel.net server on this port.
465SMTP, SSL/TLSHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (40)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (41)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (42)

Important:

cPanel & WHM strongly recommends that you enable Transport Layer Security (TLS) protocol version 1.2 on your server.

579cPHulkHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (43)This port should only accept connections on the 127.0.0.x IPv4 address. Your system does not require that this port accept external traffic.
587EximHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (44)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (45)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (46)
783Apache SpamAssassin™How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (47)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (48)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (49)
873rsyncHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (50)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (51)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (52)
953PowerDNSHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (53)This port should only accept connections on the 127.0.0.1 IPv4 address. Your system does not require that this port accept external traffic.

Note:

You must use this port when you run PowerDNS nameservers.

993IMAP SSLHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (54)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (55)
995POP3 SSLHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (56)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (57)
2077WebDAVHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (58)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (59)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (60)cPanel’s Web Disk interface (cPanel » Home » Files » Web Disk) uses these ports.
2078WebDAV SSLHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (61)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (62)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (63)
2079CalDAV and CardDAVHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (64)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (65)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (66)
2080CalDAV and CardDAV (SSL)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (67)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (68)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (69)
2082cPanel and cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (70)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (71)

Note:

To disable insecure logins via this port and only allow SSL logins, set the Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as “Always redirect to SSL/TLS” setting to On in WHM’s Tweak Settings interface (WHM » Home » Server Configuration » Tweak Settings). This will redirect users to secure ports with the /cpanel, /whm, and /webmail aliases.

2083cPanel SSL and cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (72)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (73)
2086WHM and cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (74)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (75)

Note:

To disable insecure logins via this port and only allow SSL logins, set the Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as “Always redirect to SSL/TLS” setting to On in WHM’s Tweak Settings interface (WHM » Home » Server Configuration » Tweak Settings). This will redirect users to secure ports with the /cpanel, /whm, and /webmail aliases.

2087WHM SSL and cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (76)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (77)
2089cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (78)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (79)

Important:

You must configure your system to permit outbound TCP connections from source ports 4 and 1020 to destination port 2089. This will allow the server to contact the cPanel, L.L.C. license servers.

2091Exchange ActiveSync (EAS) SSL/TLSHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (80)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (81)This port allows users of Android™ devices to synchronize their calendars, contacts, and email via the EAS protocol.

Note:

This functionality is only available if you install both the Calendars and Contacts Server and Z-Push - ActiveSync Support plugins.

2095WebmailHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (82)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (83)

Note:

To disable insecure logins via this port and only allow SSL logins, set the Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as “Always redirect to SSL/TLS” setting to On in WHM’s Tweak Settings interface (WHM » Home » Server Configuration » Tweak Settings). This will redirect users to secure ports with the /cpanel, /whm, and /webmail aliases.

2096Webmail SSL and cPanel LicensingHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (84)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (85)
2195Apple Push Notification service (APNs)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (86)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (87)cPanel & WHM only uses this port for the Apple® Push Notification Service (APNs). For more information, read our How to Set Up iOS Push Notifications documentation.
2703RazorHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (88)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (89)SpamAssassin uses the collaborative Razor spam-tracking database.
3306MySQL®How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (90)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (91)MySQL uses this port for remote database connections.
6277DCCHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (92)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (93)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (94)For more information, read the Apache® DCC and NetTestFirewallIssues documentation.
11371aptHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (95)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (96)Servers running the Ubuntu® operating system use this port to download apt repository GPG keys.
24441PyzorHow to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (97)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (98)How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (99)For more information, read Apache’s Pyzor and NetTestFirewallIssues documentation.

The License Callback Mechanism

The License Callback Mechanism immediately updates a server after the license changes in either Manage2 or the cPanel Store. It cannot make any changes to the server. It only alerts the server that a change as been made to the license. The license callback mechanism tries the following ports until one succeeds:

ServicePortInboundOutbound
cPanel2082How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (100)
cPanel SSL2083How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (101)
WHM2086How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (102)
WHM SSL2087How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (103)
Webmail SSL2096How to Configure Your Firewall for cPanel & WHM Services | cPanel & WHM Documentation (2023) (104)

Note:

At least one port in the above table must be open for the license callback mechanism to work. The server only accepts requests to this API from cPanel & WHM. The license system does not send any other information to the customer’s server.

Example configurations

Important:

  • We do not recommend that you use these examples for your personal configurations. Instead, make certain that your firewall rules match the way in which you use cPanel & WHM’s services.
  • AlmaLinux, CloudLinux 8 or higher, and Rocky Linux™ servers have additional requirements. For more information, read the AlmaLinux, Rocky Linux, and CloudLinux 8+ firewall management section below.
  • CentOS 7, CloudLinux™ 7, and Red Hat® Enterprise Linux® (RHEL) 7 servers have additional requirements. For more information, read the CentOS 7, CloudLinux 7, and RHEL 7 firewall management section below.
  • We recommend the nftables utility for servers that run the AlmaLinux OS 8, Rocky Linux 8, or CloudLinux 8 operating systems. For servers that run the CentOS 7, CloudLinux 7, or RHEL 7 operating systems, we recommend that you use the firewalld utility. We recommend the iptables utility on servers that run the Ubuntu operating system.

AlmaLinux, Rocky Linux, and CloudLinux 8+ firewall management

Important:

(Video) How To Install & Configure CSF Firewall on cPanel Server or VPS

We strongly recommend that you use the nftables framework for the firewall of servers that run the Rocky Linux, CloudLinux 8 or higher, or AlmaLinux operating systems.

Use the nftables framework instead of the iptables utility or legacy services in those operating systems. You can configure nftables with the nft command line tool. You will find the nftables ruleset for your server in the /etc/sysconfig/nftables.conf file.

For example, to block traffic for a single IPv4 address, run the following command, where 198.51.100.1 is the IPv4 address that you wish to block:

nft add rule filter INPUT ip saddr 198.51.100.1 drop

To block traffic for a single IPv6 address, run the following command, where 2001:0db8:0:0:1:0:0:1 is the IPv6 address that you wish to block:

nft add rule ip6 filter INPUT ip6 saddr [2001:0db8:0:0:1:0:0:1] drop

For more information about the nftables framework and the nft tool, read Red Hat’s Getting Started with nftables documentation.

(Video) WHM (CPanel) Original Setup Walkthrough

CentOS 7, CloudLinux 7, and RHEL 7 firewall management

We strongly recommend that servers that run the CentOS 7, CloudLinux 7, and RHEL 7 operating systems use the firewalld daemon instead of the iptables utility or legacy services in those operating systems.

For example, to block traffic for a single IPv4 address, run the following command, where 198.51.100.1 is the IPv4 address that you wish to block:

firewall-cmd --add-rich-rule='rule family="ipv4" source address="198.51.100.1" drop' --permanent

To block traffic for a single IPv6 address, run the following command, where 2001:0db8:0:0:1:0:0:1 is the IPv6 address that you wish to block:

firewall-cmd --add-rich-rule='rule family="ipv6" source address="[2001:0db8:0:0:1:0:0:1]" drop' --permanent

Important:

(Video) WHM Cpanel Install Complite Install Dediceted Server And Full Configuration

We recommend that you only use the firewall utilities on CentOS 7, CloudLinux 7, and RHEL 7 servers.

  • If you use firewalld, you must enable the daemon before you change the firewall settings. To do this, run the systemctl enable firewalld command. If you do not enable the daemon, the system will erase any firewall changes when you reboot the server.
  • If you use firewalld, the system will remove the iptables-services package through the yum package manager with the following command: yum remove iptables-services
  • If you use the the legacy iptables utility, remove the firewalld package through the yum package manager with the following command: yum remove firewalld
  • If you use a third-party firewall management service, we recommend that you check the firewall’s documentation before you remove the unused firewalld or iptables packages.

For more information about the firewall utilities and the firewalld daemon, read Red Hat’s Using Firewalls documentation.

The cpanel service

Important:

The /usr/local/cpanel/scripts/configure_firewall_for_cpanel script clears all existing rule entries from your server’s iptables utility. If you use custom rules for your firewall, export those rules before you run the script and then re-add them afterward.

cPanel & WHM also includes the cpanel service, which manages all of the rules in the /etc/firewalld/services/cpanel.xml file. This allows TCP access for the server’s ports.

To replace your server’s existing iptables rules with the rules in the /etc/firewalld/services/cpanel.xml file, perform the following steps:

  1. Run the yum install firewalld command to ensure that you have installed the firewalld service daemon on your system.
  2. Run the systemctl start firewalld.service command to start the firewalld service.
  3. Run the systemctl enable firewalld command to start the firewalld service when the server starts.
  4. Run the iptables-save > backupfile command to save your existing firewall rules.
  5. Run the /usr/local/cpanel/scripts/configure_firewall_for_cpanel script.
  6. Run the iptables-restore < backupfile command to incorporate your old firewall rules into the new firewall rules file.

Ubuntu firewall management

We recommend that servers that run the Ubuntu operating systems use the iptables utility instead of the ufw utility that Ubuntu installs by default. The iptables utility offers more customization settings for your packet-filtering rules.

Note:

This utility requires that you understand the TCP/IP stack. For more information about the use of iptables, visit the iptables site, or run the man iptables command from the command line.

(Video) SSL/TLS - cPanel & WHM | How to install SSL certificate in WHM & cPanel | WHM Mastering Course Ep23

For example, to block traffic for a single IPv4 address, run the following command, where 198.51.100.1 is the IPv4 address that you wish to block:

iptables -I INPUT -s 198.51.100.1 -j DROP

(Video) How to Install Cpanel WHM and Configuration

To block traffic for a single IPv6 address, run the following command, where 2001:0db8:0:0:1:0:0:1 is the IPv6 address that you wish to block:

ip6tables -I INPUT -s 2001:0db8:0:0:1:0:0:1 -j DROP

Adding rules with the CSF and APF utilities

The following examples explain how to add rules with ConfigServer Security & Firewall (CSF) and Advanced Policy Firewall (APF).

Warning:

CSF and APF do not function with the firewalld utility. If you install CSF or APF, you must remove the firewalld utility. To do this, run the yum remove firewalld command.

Remember:

We recommend that you use the firewalld utility on servers that run the CentOS 7, CloudLinux 7, or RHEL 7 operating systems. We recommend the nftables utility for servers that run the AlmaLinux OS 8, Rocky Linux 8, or CloudLinux 8 operating systems. We recommend the iptables utility on servers that run the Ubuntu operating system.

ConfigServer Security & Firewall

ConfigServer provides the free WHM plugin CSF, which allows you to modify your server’s iptables rules in WHM. For information about how to install and configure CSF, read our Additional Security Software documentation.

Advanced Policy Firewall

APF acts as a front-end interface for the iptables utility, and allows you to open or close ports without the use of the iptables syntax.

The following example provides two rules that you can add to the /etc/apf/conf.apf file to allow HTTP and HTTPS access to your system:

123
# Common ingress (inbound) TCP portsIG_TCP_CPORTS="80,443"EG_TCP_CPORTS="80"

(Video) WHM Tutorials - How to Install cPanel & WHM

(Video) How To Install & Configure CSF Firewall on cPanel Server or VPS

1. cPanel & WHM - Security - Part 2

2. SSL/TLS - cPanel & WHM | How to install SSL certificate in WHM & cPanel | WHM Mastering Course Ep23

3. How to Install and Setup CSF Firewall, ClamAV In cPanel CentOS 7 - Make Money with Websites Part 11

4. WHM (CPanel) Original Setup Walkthrough

5. How to change WHM/cPanel update preferences

6. Step-9: WHM Security Center (WHM Configuration) ✔️

Article information

Author: Gov. Deandrea McKenzie

Last Updated: 23/01/2023

Views: 6730

Rating: 4.6 / 5 (66 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Gov. Deandrea McKenzie

Birthday: 2001-01-17

Address: Suite 769 2454 Marsha Coves, Debbieton, MS 95002

Phone: +813077629322

Job: Real-Estate Executive

Hobby: Archery, Metal detecting, Kitesurfing, Genealogy, Kitesurfing, Calligraphy, Roller skating

(Video) How To Setup A DNS Cluster In cPanel/Web Host Manager (WHM)

Introduction: My name is Gov. Deandrea McKenzie, I am a spotless, clean, glamorous, sparkling, adventurous, nice, brainy person who loves writing and wants to share my knowledge and understanding with you.

FAQs

How do I enable firewall in WHM? ›

via WHM
  1. Log into WHM.
  2. Navigate to ConfigServer Security & Firewall.
  3. Click "Firewall Enable"
Jul 14, 2021

How to install firewall in cpanel? ›

ConfigServer software
  1. Log in to your server as the root user via SSH.
  2. Run the cd /root command to change to the root directory.
  3. Run the tar -xzf csf. tgz command to decompress the downloaded file.
  4. Run the cd csf command to change directories.
  5. To begin the CSF installation, run the ./install.cpanel.sh command.
Jul 19, 2022

How do I add an IP firewall to WHM? ›

Adding your IP address to the Firewall
  1. Log into your WHM.
  2. Click the “Add IP to Firewall” link in the left menu. This link is one of the last links in the left menu in WHM. ...
  3. Enter your IP address in the “Allow Rule:” field and click the “Add Rule / Restart” button. Note!
Feb 13, 2023

Does Cpanel have a firewall? ›

One of the most-requested features on cPanel servers is the ability to manage and filter traffic at a country level. With the ConfigServer Firewall (CSF) plugin in WebHost Manager, you can do exactly that.

How do I whitelist an IP address in WHM firewall? ›

Whitelist IP Address
  • Log into WHM as the 'root' user.
  • Type “cphulk” in the search box, then click the cPHulk Brute Force Protection link in the Security Center section.
  • Click the Whitelist Management tab.
  • Add the IP addresses that you want to whitelist to the New Whitelist Records section.
Nov 19, 2021

How do I access WHM with IP address? ›

Enter the IP address or domain and the 2087 service port in your preferred browser (for example, https://198.51.100.1:2087 ).
  1. Enter your WHM username in the Username text box.
  2. Enter your password in the Password text box.
  3. Click Log in.
Jul 12, 2022

Which firewall is best for cPanel? ›

Setup ConfigServer Firewall (CSF)

CSF (ConfigServer Security and Firewall) is one of the most popular firewalls for cPanel servers.

How to install firewall step by step? ›

There are primarily four important steps in installing a network firewall security system in any network.
  1. Step 1: Secure access to the firewall. ...
  2. Step 2: Define network architecture. ...
  3. Step 3: Configure the firewall. ...
  4. Step 4: Testing of the firewall.
May 13, 2020

Where do you configure firewall? ›

Microsoft firewall settings are found through Start > Settings > Update & Security > Windows Security > Firewall and Network Protection.

How do I configure my firewall IP address? ›

To Add IP Address in Windows Firewall
  1. Select the Advanced settings option from the sidebar menu.
  2. The Windows Firewall with Advanced Security panel will open. ...
  3. Windows Firewall will open a new window New Inbound Rule Wizard. ...
  4. A form will appear in the window. ...
  5. Another window named IP Address will pop up.
Sep 16, 2021

How do I install cPanel and WHM on my server? ›

How to Install cPanel
  1. Step 1: Login to the server. Login via SSH to the server using the root username. ...
  2. Step 2: Open a screen. Install screen if it is not yet installed: ...
  3. Step 3: Set a hostname. ...
  4. Step 4: Execute the Installation Command. ...
  5. Step 5: Proceed with web installation. ...
  6. Step 6: Restart the server.
Nov 29, 2020

How do I allow IP in cPanel firewall? ›

Procedure
  1. Log into WHM as the 'root' user.
  2. Navigate to "Home / Plugins / ConfigServer Security & Firewall / Firewall Configuration."
  3. Click the "csf" tab.
  4. In the text box following "Allow IP address," Enter the IP address to be whitelisted.
  5. Click the "Quick Allow" button.
Feb 9, 2023

How do I check my cPanel firewall? ›

The cpanel service
  1. Run the yum install firewalld command to ensure that you have installed the firewalld service daemon on your system.
  2. Run the systemctl start firewalld. ...
  3. Run the systemctl enable firewalld command to start the firewalld service when the server starts.
Nov 1, 2022

What is the difference between cPanel and cPanel? ›

What Are the Differences Between cPanel and hPanel? From easy-to-follow installations to MySQL databases, hPanel appears similar to cPanel. The main difference between the two is the developer – hPanel is an in-house tool developed by Hostinger to make every customer's online experience as easy and smooth as possible.

How do I know if my IP is blocked by cPanel firewall? ›

Step 1 − Open cPanel IP Blocker by clicking on IP Blocker Link found under security section of cPanel Home. Step 2 − Scroll down to find Currently–Blocked IP Addresses. Find the IP address or Range you want to remove, and click on Delete link.

Which IP address is used to whitelist? ›

IP whitelisting is when you grant network access only to specific IP addresses. Each employee (or approved user) shares their home IP address with the network administrator, who then enters their IP address on a “whitelist” that grants them network access.

What is blacklist and whitelist IP? ›

Whitelisting and blacklisting are two methodologies to control access to websites, email, software and IP addresses on networks. Whitelisting denies access to all resources and only the “owner” can allow access. Blacklisting allows access to all with the provision that only certain items are denied.

How do I check my WHM server configuration? ›

To view your server's information:
  1. Log in to WHM.
  2. Using the search box either on the left-side panel or at the top of the page, search for the Server Information section.
  3. Select Server Information from the list.
  4. The Server Information page gives us information about the specific hardware configuration of the server.

What is my WHM Username and password? ›

In the Welcome email, you will find: WHM Address - This is your WHM's URL and usually ends with ":2087." You may want to open that link in a browser and bookmark the URL. Username - This is your WHM's username. Password - You now have the option to set your root password upon receiving the Welcome email.

How do I check my WHM server space? ›

How to View Disk Space Usage
  1. Login to your WHM.
  2. Type “list” in the search box.
  3. Click the List Accounts link which is under the Account Information heading in the left menu. You will see a listing of all of your accounts, and disk space usage can be seen under the “Disk Used” column.
Aug 22, 2022

What are the 3 types of cPanel users? ›

The account tiers are separated into Solo, Admin, Pro, and Premier account tiers. The main difference between these tiers is the number of cPanel user accounts available to be created as well as the monthly pricing.

What is the strongest type of firewall? ›

Proxy Firewalls (Application-Level Gateways)

As the most powerfully secure choice available, proxy firewalls serve as an intermediary where source computers connect to the proxy instead of the destination device.

Which 5 a firewall using is the most secure type of firewall? ›

Proxy servers are the most secure type of firewall, as they filter packets through a protected proxy server. This is done before traffic even reaches the network perimeter.

What are the five 5 steps to configure a firewall? ›

Here is how to configure a firewall securely:
  1. Secure the Firewall. ...
  2. Establish Firewall Zones and an IP Address Structure. ...
  3. Configure Access Control Lists (ACLs) ...
  4. Configure Other Firewall Services and Logging. ...
  5. Test the Firewall Configuration. ...
  6. Manage Firewall Continually.

What is basic firewall configuration? ›

Firewall configuration involves configuring domain names and Internet Protocol (IP) addresses and completing several other actions to keep firewalls secure. Firewall policy configuration is based on network types called “profiles” that can be set up with security rules to prevent cyber attacks.

What is the proper rule for a firewall? ›

Firewall rules: Determine what traffic your firewall allows and what is blocked. Examine the control information in individual packets, and either block or allow them according to the criteria that you define. Control how the firewalls protect your network from malicious programs and unauthorized access.

How do I configure firewall on my client computer? ›

Open Control Panel and double-click System and Security. Select Windows Firewall. Select Allow a program or feature through Windows Firewall. Select the Change settings option.

How to activate firewall? ›

Enabling Your Windows Firewall
  1. Open the Control Panel in Windows.
  2. Click on System and Security.
  3. Click on Windows Firewall.
  4. If your firewall is disabled, you'll see Windows Firewall marked “Off.” To turn it on, in the left navigation pane, you can click on Turn Windows Firewall on or off.

How do I enable Apache in WHM? ›

How to install an Apache module in WHM
  1. Log into WHM.
  2. Navigate to EasyApache 4.
  3. Click Customize under Currently Installed Packages.
  4. Click Apache Modules.
  5. Use the search bar to search for the extension you need to install. ...
  6. Mark the module for installation by clicking the switch icon to the far right of the extension.
Sep 8, 2020

How do I restrict access to a country in WHM? ›

How to block WHM server access for specific countries? Print
  1. First, log into WHM as the 'root' user.
  2. Click the cPHulk Brute Force Protection link in the Security Center section after entering "cphulk" in the search box.
  3. Go to the cPHulk Brute Force Protection website and click the Countries Management option.

How do I find my firewall settings? ›

Click the Start button, then type Windows Firewall in the Search box. Click Windows Firewall, and then click Allow a program or feature through Windows Firewall. Click the Change settings button. If a User Account Control window appears, click Yes, or enter your user name and password, then click OK.

How do I know if my firewall is open? ›

How to check if Windows Firewall is blocking a program
  1. Press Windows Key + R to open Run.
  2. Type "control" and press OK to open Control Panel.
  3. Click on System and Security.
  4. Click on Windows Defender Firewall.
  5. From the left panel Allow an app or feature through Windows Defender Firewall.
Apr 3, 2023

What is Apache WHM? ›

Apache web server is the most important part of your WHM server. It's the program that allows visitors to view your websites.

How to access WHM through SSH? ›

Log in with a SSH Key
  1. Open a Terminal session.
  2. Run the following command: ssh -p port -i ssh-key user@IP where port represents the port number, ssh-key represents the file path to your SSH key, user represents your username, and IP represents your IP address. For example: ...
  3. Enter your SSH key password.
Nov 30, 2022

How to install PHP in WHM? ›

To install a PHP version in WHM, you may follow these steps:
  1. Log into WHM as the root user.
  2. Navigate to EasyApache 4.
  3. Click "Customize"under "Currently Installed Packages."
  4. Click "PHP Versions."
  5. Mark the version for installation by clicking the switch icon to the far right of the version.
Nov 7, 2022

How do I find my blocked IP address in WHM? ›

Click on ConfigServer Security & Firewall under Plugins.
  1. Then find Search for IP.
  2. Enter the IP address and click on Search for IP.
  3. Then you will get the results as follows:
  4. If you want to unblock the IP address, then click the Unblock button on bottom of the page.

How do I unblock a port on WHM? ›

Login to your Linux Server through SSH.
...
  1. Login to WHM.
  2. Type firewall in Find bar and click on ConfigServer Security&Firewall link.
  3. Click on the Firewall Configuration button.
  4. Scroll down and locate Allow incoming TCP ports section. ...
  5. Lastly, you will need to restart csf by clicking on Restart csf+lfd button.
Aug 27, 2018

How do I make WHM secure? ›

To reduce security risks, disable all services and daemons that you do not use. Disable any services that you do not currently use with WHM's Service Manager interface (WHM » Home » Service Configuration » Service Manager).

Videos

1. cPanel & WHM - Security - Part 2
(REGXA)
2. WHM Security Centre Basics – Onlive Server
(Onlive Server Private Limited)
3. [🔴LIVE] How to change SSH port via WHM root?
(Red Server Host)
4. What are the various ways to access WHM Root [EXPLAINED]☑️
(Red Server Host)
5. How to enable IP and Port in WHM?
(Roel Van de Paar)
6. WHM FTP Passive Mode Solution [Problem Fix New WHM Server FTP not connecting] ✔️
(BIKIRAN)
Top Articles
Latest Posts
Article information

Author: Jerrold Considine

Last Updated: 03/24/2023

Views: 5901

Rating: 4.8 / 5 (58 voted)

Reviews: 81% of readers found this page helpful

Author information

Name: Jerrold Considine

Birthday: 1993-11-03

Address: Suite 447 3463 Marybelle Circles, New Marlin, AL 20765

Phone: +5816749283868

Job: Sales Executive

Hobby: Air sports, Sand art, Electronics, LARPing, Baseball, Book restoration, Puzzles

Introduction: My name is Jerrold Considine, I am a combative, cheerful, encouraging, happy, enthusiastic, funny, kind person who loves writing and wants to share my knowledge and understanding with you.