MegaWit Firewall (MWF) is a modern iptables/ipset firewall with built-in brute-force protection for cPanel & WHM. Manage allow, deny and ignore lists, auto-ban attackers hammering SSH, mail, Exim, cPanel and FTP, and control it all from a WHM dashboard — everything ConfigServer Security & Firewall (csf + lfd) did, rebuilt for today.
Control which ports are open, block by country, ASN and blocklist, stop brute-force logins and floods, and manage it all from WHM — no config files, no lock-outs.
A dedicated MWF chain backed by ipsets — fast even with hundreds of thousands of blocked networks. Runs from CentOS 7 to EL9, Ubuntu & Debian, coexisting with or replacing csf.
Allow only the TCP/UDP ports you choose, inbound and outbound — block everything else. The csf "allow-only ports" model, with a one-click toggle.
Even with default-deny on, your SSH port and established connections always pass — and a TESTING timer auto-reverts the policy if you don't confirm you're still connected.
Scans SSH, mail/Dovecot, Exim SMTP-AUTH, cPanel and FTP logs and auto-bans IPs with too many failed logins — with tunable thresholds and windows.
Open a port to a single source ("MySQL from the office only"), or block a specific protocol/port — inbound or outbound, IPv4 & IPv6.
Block or allow whole countries by ISO code. GeoIP ranges are downloaded and refreshed nightly, and your allow-list always wins.
Block entire networks by autonomous-system number, and subscribe to curated blocklists — FireHOL, Spamhaus DROP/eDROP, DShield, Emerging Threats.
Rate-limit new connections per source, cap concurrent connections per IP and set per-port flood limits — blunt SYN floods and port scans.
Permanently block, always-trust, or exempt-from-auto-ban any IP or CIDR — IPv4 and IPv6, applied live with no restart.
Auto-expiring bans with per-entry timeouts (1 hour, 24 hours, 7 days or permanent) — attackers are dropped now and cleaned up automatically.
Active bans, 24-hour auto-bans, list sizes, port-policy state and license status at a glance — a real control panel, not a shell script. Multi-language.
Choose which events (bans, floods, GeoIP refresh, license) notify you — over Email, Slack, Telegram or webhook, instantly or as a daily digest.
See what's being blocked, ban or unban an IP and tune brute-force protection right from WHM — no SSH required.
ConfigServer Security & Firewall (csf + lfd) is powerful but config-file driven and no longer actively developed. Here's how MWF compares.
| Capability | MegaWit Firewall | ConfigServer csf/lfd | Imunify360 (firewall) |
|---|---|---|---|
| iptables / ipset firewall | ✓ | ✓ | ✓ |
| Port policy (allow-only ports) | ✓ | ✓ | ✓ |
| Brute-force login protection | ✓ | ✓ (lfd) | ✓ |
| Advanced IP + port rules | ✓ | ✓ | Partial |
| Country (GeoIP) blocking | ✓ | ✓ | ✓ |
| ASN & public blocklists | ✓ | ✓ | Partial |
| SYN-flood / port-flood protection | ✓ | ✓ | ✓ |
| Allow / Deny / Ignore lists + temp bans | ✓ | ✓ | ✓ |
| Full WHM dashboard (no config files) | ✓ | Basic UI | ✓ |
| Lockout-proof default-deny (tested) | ✓ | Manual | ✓ |
| Multi-language panel + alert matrix | ✓ | ✗ | Partial |
| Actively maintained | ✓ | Minimal | ✓ |
| Price | $14.99/mo | free | $$$ higher |
No credit card. The trial activates automatically on first install — one per server. Your existing firewall is left untouched.
SSH into your cPanel/WHM server (CentOS 7+, CloudLinux, AlmaLinux, Rocky, Ubuntu or Debian).
This installs the agent, sets up the firewall and brute-force protection, the WHM panel, and starts your 15-day trial automatically. It ships with a safe rule set — nothing is blocked until you say so.
Go to WHM » Plugins » MegaWit Firewall for live bans, IP lists and brute-force settings.
Buy a key, then paste it in WHM » MegaWit Firewall » Settings » License — no SSH required. It binds to this server and unlocks continuous protection after the trial.
No per-account fees. Protect the whole server — every cPanel account — for one flat price.
Pair it with MegaWit Shield and MegaWit Postmaster for full server security, mail & firewall protection.
Yes. MWF is a modern replacement for csf + lfd. It gives you an iptables/ipset firewall with allow, deny and ignore lists plus brute-force login protection across SSH, mail, Exim, cPanel and FTP — all from a full WHM dashboard instead of config files. It can run alongside csf during migration or fully replace it.
No. MWF has no default-deny policy — it only drops the IPs and ranges you deny or that the brute-force daemon bans, and your allow list is always accepted first. Your active SSH session and trusted IPs stay reachable, by design.
Yes. MWF uses its own dedicated iptables chain and ipsets, so it coexists with csf/firewalld without conflict. That lets you migrate gradually — then remove csf once you're comfortable.
A lightweight daemon (lfd equivalent) incrementally scans auth logs for failed logins per source IP over a sliding window. When an IP crosses your threshold it's auto-banned with an expiry you choose, and you get an alert. Allow/ignore-listed IPs are never auto-banned.
Run the one-line installer and a 15-day trial activates automatically — one per server, no credit card. One license = one server with unlimited cPanel accounts; it binds to the server by hardware fingerprint and can be moved from your billing panel anytime.
CentOS 7+, CloudLinux, AlmaLinux, Rocky Linux, Ubuntu and Debian — anywhere cPanel/WHM runs, using iptables + ipset. The agent is a single static Go binary with no dependencies.
Start a free 15-day trial in minutes, or grab a license and put a modern firewall in front of your server today.