{"id":678,"date":"2021-07-23T12:35:27","date_gmt":"2021-07-23T12:35:27","guid":{"rendered":"https:\/\/ssdsunucum.com\/blog\/how-to-configure-your-firewall-for-cpanel-whm-services\/"},"modified":"2021-07-23T12:35:27","modified_gmt":"2021-07-23T12:35:27","slug":"how-to-configure-your-firewall-for-cpanel-whm-services","status":"publish","type":"post","link":"https:\/\/ssdsunucum.com\/blog\/how-to-configure-your-firewall-for-cpanel-whm-services\/","title":{"rendered":"How to Configure Your Firewall for cPanel &#038; WHM Services"},"content":{"rendered":"<\/p>\n<div class=\"col-md-9\">\n<div class=\"flex-column flex-md-row article-header\">\n<div id=\"versioned-article-header\">\n<p class=\"valid-version-info\"><em>Valid for versions 94 through the latest version<\/em><\/p>\n<\/div>\n<div id=\"version-select-group\" aria-label=\"select versions\">\n<h4>Version:<\/h4>\n<h4>84<\/h4>\n<h4>86<\/h4>\n<h4>90<\/h4>\n<h4>92<\/h4>\n<h4>94<\/h4>\n<\/div><\/div>\n<hr>\n<h2 id=\"overview\">Overview<\/h2>\n<p>cPanel &#038; WHM installs and manages many different services on your system, most of which require an external connection in order to function properly. Because of this, your firewall <strong>must<\/strong> allow cPanel &#038; WHM to open the ports on which these services run.<\/p>\n<p>This document lists the ports that cPanel &#038; WHM uses, and which services use each of these ports, to allow you to better configure your firewall.<\/p>\n<div class=\"callout callout-danger\">\n<div class=\"callout-heading\">Warning:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>We <strong>strongly<\/strong> recommend that you <strong>only<\/strong> open ports for services that you use.<\/li>\n<li>When you work with firewall rules, <strong>always<\/strong> make certain to include a way to log back in to your server, and <strong>always<\/strong> maintain console access to your server.<\/li>\n<\/ul><\/div>\n<\/div>\n<h2 id=\"ports\">Ports<\/h2>\n<div class=\"callout callout-danger\">\n<div class=\"callout-heading\">Warning:<\/div>\n<div class=\"callout-content\">\n<p>We <strong>strongly<\/strong> recommend that you use the SSL version of each service whenever possible:<\/p>\n<ul>\n<li>The use of non-SSL services can allow attackers to intercept sensitive information, such as login credentials.<\/li>\n<li>Always ensure that valid SSL certificates exist for your services in WHM\u2019s <em>Manage Service SSL Certificates<\/em> interface (<em>WHM &gt;&gt; Home &gt;&gt; Service Configuration &gt;&gt; Manage Service SSL Certificates<\/em>).<\/li>\n<\/ul><\/div>\n<\/div>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>For more information on how to access cPanel &#038; WHM services, read our How to Access cPanel &#038; WHM Services documentation.<\/p>\n<\/p><\/div>\n<\/div>\n<p>cPanel &#038; WHM uses the following ports:<\/p>\n<table>\n<thead>\n<tr>\n<th>Port<\/th>\n<th>Service<\/th>\n<th>TCP<\/th>\n<th>UDP<\/th>\n<th>Inbound<\/th>\n<th>Outbound<\/th>\n<th>Localhost<\/th>\n<th>Notes<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td><code>1<\/code><\/td>\n<td>CPAN<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>The <em>Show Available Modules<\/em> setting in cPanel\u2019s <em>Perl Modules<\/em> interface (<em>cPanel &gt;&gt; Home &gt;&gt; Software &gt;&gt; Perl Modules<\/em>) uses this port to improve the speed in which it appears.<\/td>\n<\/tr>\n<tr>\n<td><code>20<\/code><\/td>\n<td>FTP<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>Instead of FTP, we recommend that you use the more-secure SFTP via SSH.<\/td>\n<\/tr>\n<tr>\n<td><code>21<\/code><\/td>\n<td>FTP<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>22<\/code><\/td>\n<td>SSH<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td>You must open this port <strong>before<\/strong> you use WHM\u2019s <em>Transfer Tool<\/em> interface (<em>WHM &gt;&gt; Home &gt;&gt; Transfers &gt;&gt; Transfer Tool<\/em>) when:<\/p>\n<ul>\n<li>You authenticate <code>root<\/code> users with SSH keys.<\/li>\n<li>You are transferring from a server on cPanel &#038; WHM version 88 or earlier.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><code>25<\/code><\/td>\n<td>SMTP<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>26<\/code><\/td>\n<td>SMTP<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>cPanel &#038; WHM <strong>only<\/strong> uses this port if you specify it in WHM\u2019s <em>Service Manager<\/em> interface (<em>WHM &gt;&gt; Home &gt;&gt; Service Configuration &gt;&gt; Service Manager<\/em>).<\/td>\n<\/tr>\n<tr>\n<td><code>37<\/code><\/td>\n<td><code>rdate<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>43<\/code><\/td>\n<td><code>whois<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>53<\/code><\/td>\n<td>DNS<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>cPanel &#038; WHM uses this port for the following functions:<\/p>\n<ul>\n<li>Public DNS services.<\/li>\n<li>Communication with <code>root<\/code> nameservers for AutoSSL.<\/li>\n<li>Other functions that require name resolution.<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td><code>80<\/code><\/td>\n<td><code>httpd<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>This port serves the HTTP needs of services on the server. <\/p>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>We <strong>strongly<\/strong> recommend that you encourage your users to use port <code>443<\/code>, which uses the more secure SSL\/TLS security protocol. For more information, read our More about TLS and SSL documentation.<\/li>\n<li>The cPanel Server Daemon (<code>cpsrvd<\/code>) listens on this port when you <strong>disable<\/strong> the Web Server role. This daemon monitors cPanel &#038; WHM services.<\/li>\n<\/ul><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>110<\/code><\/td>\n<td>POP3<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>113<\/code><\/td>\n<td><code>ident<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>143<\/code><\/td>\n<td>IMAP<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>443<\/code><\/td>\n<td><code>httpd<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>This port serves the HTTPS needs of services on the server. <\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>This port can allow users to access cPanel or WHM via certain subdomains. For more information, read our Service and Proxy Subdomains documentation.<\/li>\n<li>The cPanel Server Daemon (<code>cpsrvd<\/code>) listens on this port when you <strong>disable<\/strong> the Web Server role.<\/li>\n<li>WHM\u2019s <em>Manage AutoSSL<\/em> interface (<em>WHM &gt;&gt; Home &gt;&gt; SSL\/TLS &gt;&gt; Manage AutoSSL<\/em>) requires outbound access to the <code>store.cpanel.net<\/code> server.<\/li>\n<\/ul><\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>465<\/code><\/td>\n<td>SMTP, SSL\/TLS<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n        cPanel &#038; WHM <strong>strongly<\/strong> recommends that you enable Transport Layer Security (TLS) protocol version 1.2 on your server.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>579<\/code><\/td>\n<td>cPHulk<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td>This port should <strong>only<\/strong> accept connections on the <code>127.0.0.x IPv4<\/code> address. Your system does <strong>not<\/strong> require that this port accept external traffic.<\/td>\n<\/tr>\n<tr>\n<td><code>587<\/code><\/td>\n<td>Exim<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>783<\/code><\/td>\n<td>Apache SpamAssassin\u2122<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>873<\/code><\/td>\n<td>rsync<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>953<\/code><\/td>\n<td>PowerDNS<\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td>This port should <strong>only<\/strong> accept connections on the <code>127.0.0.1 IPv4<\/code> address. Your system does <strong>not<\/strong> require that this port accept external traffic. <\/p>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n        You <strong>must<\/strong> use this port when you run PowerDNS nameservers.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>993<\/code><\/td>\n<td>IMAP SSL<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>995<\/code><\/td>\n<td>POP3 SSL<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2077<\/code><\/td>\n<td>WebDAV<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>cPanel\u2019s <em>Web Disk<\/em> interface (<em>cPanel &gt;&gt; Home &gt;&gt; Files &gt;&gt; Web Disk<\/em>) uses these ports.<\/td>\n<\/tr>\n<tr>\n<td><code>2078<\/code><\/td>\n<td>WebDAV SSL<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2079<\/code><\/td>\n<td>CalDAV and CardDAV<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2080<\/code><\/td>\n<td>CalDAV and CardDAV (SSL)<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2082<\/code><\/td>\n<td>cPanel and cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n        To disable logins via this port and only allow SSL logins, set the <em>Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs<\/em>. Formerly known as <em>\u201cAlways redirect to SSL\/TLS\u201d<\/em> setting to <em>On<\/em> in WHM\u2019s <em>Tweak Settings<\/em> interface (<em>WHM &gt;&gt; Home  &gt;&gt; Server Configuration &gt;&gt; Tweak Settings<\/em>). This will redirect users to secure ports with the <code>\/cpanel<\/code>, <code>\/whm<\/code>, and <code>\/webmail<\/code> aliases.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>2083<\/code><\/td>\n<td>cPanel SSL and cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2086<\/code><\/td>\n<td>WHM and cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n        To disable logins via this port and only allow SSL logins, set the <em>Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as \u201cAlways redirect to SSL\/TLS\u201d<\/em> setting to <em>On<\/em> in WHM\u2019s <em>Tweak Settings<\/em> interface (<em>WHM &gt;&gt; Home  &gt;&gt; Server Configuration &gt;&gt; Tweak Settings<\/em>). This will redirect users to secure ports with the <code>\/cpanel<\/code>, <code>\/whm<\/code>, and <code>\/webmail<\/code> aliases.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>2087<\/code><\/td>\n<td>WHM SSL and cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2089<\/code><\/td>\n<td>cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n        You <strong>must<\/strong> configure your system to permit outbound tcp connections from source ports <code>4<\/code> and <code>1020<\/code> to destination port <code>2089<\/code>. This will allow the server to contact the cPanel, L.L.C. license servers.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>2095<\/code><\/td>\n<td>Webmail<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n        To disable logins via this port and only allow SSL logins, set the <em>Choose the closest matched domain for which that the system has a valid certificate when redirecting from non-SSL to SSL URLs. Formerly known as \u201cAlways redirect to SSL\/TLS\u201d<\/em> setting to <em>On<\/em> in WHM\u2019s <em>Tweak Settings<\/em> interface (<em>WHM &gt;&gt; Home  &gt;&gt; Server Configuration &gt;&gt; Tweak Settings<\/em>). This will redirect users to secure ports with the <code>\/cpanel<\/code>, <code>\/whm<\/code>, and <code>\/webmail<\/code> aliases.\n    <\/div>\n<\/div>\n<\/td>\n<\/tr>\n<tr>\n<td><code>2096<\/code><\/td>\n<td>Webmail SSL and cPanel Licensing<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td><code>2195<\/code><\/td>\n<td>Apple Push Notification service (APNs)<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>cPanel &#038; WHM only uses this port for the Apple\u00ae Push Notification Service (APNs). For more information, read our How to Set Up iOS Push Notifications  documentation.<\/td>\n<\/tr>\n<tr>\n<td><code>2703<\/code><\/td>\n<td>Razor<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>Razor is a collaborative spam-tracking database.<\/td>\n<\/tr>\n<tr>\n<td><code>3306<\/code><\/td>\n<td>MySQL\u00ae<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><\/td>\n<td>MySQL uses this port for remote database connections.<\/td>\n<\/tr>\n<tr>\n<td><code>6277<\/code><\/td>\n<td>DCC<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>For more information, read the Apache\u00ae DCC and NetTestFirewallIssues documentation.<\/td>\n<\/tr>\n<tr>\n<td><code>24441<\/code><\/td>\n<td>Pyzor<\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<td>For more information, read Apache\u2019s Pyzor and NetTestFirewallIssues documentation.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h3 id=\"the-license-callback-mechanism\">The License Callback Mechanism<\/h3>\n<p>The License Callback Mechanism immediately updates a server after the license changes in either Manage2 or the cPanel Store. It cannot make any changes to the server. It <strong>only<\/strong> alerts the server that a change as been made to the license. The license callback mechanism tries the following ports until one succeeds:<\/p>\n<table>\n<thead>\n<tr>\n<th>Service<\/th>\n<th>Port<\/th>\n<th>Inbound<\/th>\n<th>Outbound<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>cPanel<\/td>\n<td><code>2082<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>cPanel SSL<\/td>\n<td><code>2083<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>WHM<\/td>\n<td><code>2086<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>WHM SSL<\/td>\n<td><code>2087<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<tr>\n<td>Webmail SSL<\/td>\n<td><code>2096<\/code><\/td>\n<td><img src=\"https:\/\/ssdsunucum.com\/blog\/wp-content\/uploads\/2021\/07\/checkbox-4.png\" title=\"checkbox-4\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>At least one port in the above table <strong>must<\/strong> be open for the license callback mechanism to work. The server only accepts requests to this API from cPanel &#038; WHM. The license system does <strong>not<\/strong> send any other information to the customer\u2019s server.<\/p>\n<\/p><\/div>\n<\/div>\n<h2 id=\"example-configurations\">Example configurations<\/h2>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<ul>\n<li>We do <strong>not<\/strong> recommend that you use these examples for your personal configurations. Instead, make <strong>certain<\/strong> that your firewall rules match the way in which you use cPanel &#038; WHM\u2019s services.<\/li>\n<li>CentOS 8, AlmaLinux 8, and CloudLinux\u2122 8 servers have additional requirements. For more information, read the CentOS 8, AlmaLinux 8, and CloudLinux 8 firewall management section below.<\/li>\n<li>CentOS 7, CloudLinux\u2122 7, and Red Hat\u00ae Enterprise Linux\u00ae (RHEL) 7 servers have additional requirements. For more information, read the CentOS 7, CloudLinux 7, and RHEL 7 firewall management section below.<\/li>\n<li>Red Hat Enterprise Linux 8 deprecated the <code>iptables<\/code> utility. While cPanel, L.L.C. does not support this version of RHEL, this change affects all cPanel-supported operating systems. We recommend the <code>nftables<\/code> utility for servers that run CentOS 8, AlmaLinux 8, or CloudLinux 8. For servers that run CentOS 7, CloudLinux 7, or RHEL 7, we recommend that you use the <code>firewalld<\/code> utility. For more information, read Red Hat\u2019s When to use firewalld, nftables, or iptables documentation.<\/li>\n<\/ul><\/div>\n<\/div>\n<h3 id=\"centos-8-almalinux-8-and-cloudlinux-8-firewall-management\">CentOS 8, AlmaLinux 8, and CloudLinux 8 firewall management<\/h3>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<p>We <strong>strongly<\/strong> recommend that you use the <code>nftables<\/code> framework for your CentOS 8, AlmaLinux 8, or CloudLinux 8 firewall.<\/p>\n<\/p><\/div>\n<\/div>\n<p>Use the <code>nftables<\/code> framework instead of <code>iptables<\/code> programs or legacy services in those operating systems. You can configure <code>nftables<\/code> with the <code>nft<\/code> command line tool. You will find the <code>nftables<\/code> ruleset for your server in the <code>\/etc\/sysconfig\/nftables.conf<\/code> file.<\/p>\n<p>For example, to block traffic for a single IPv4 address, run the following command, where <code>192.168.0.0<\/code> is the IPv4 address that you wish to block:<\/p>\n<pre><code>nft add rule filter INPUT ip saddr 192.168.0.0 drop\n<\/code><\/pre>\n<p>To block traffic for a single IPv6 address, run the following command, where <code>2001:0db8:0:0:1:0:0:1<\/code> is the IPv6 address that you wish to block:<\/p>\n<pre><code>nft add rule ip6 filter INPUT ip6 saddr [2001:0db8:0:0:1:0:0:1] drop\n<\/code><\/pre>\n<p>For more information about the <code>nftables<\/code> framework and the <code>nft<\/code> tool, read Red Hat\u2019s Getting Started with nftables documentation.<\/p>\n<h3 id=\"centos-7-cloudlinux-7-and-rhel-7-firewall-management\">CentOS 7, CloudLinux 7, and RHEL 7 firewall management<\/h3>\n<p>We <strong>strongly<\/strong> recommend that servers which run the CentOS 7, CloudLinux 7, and RHEL 7 operating systems use the <code>firewalld<\/code> daemon instead of <code>iptables<\/code> programs or legacy services in those operating systems.<\/p>\n<p>For example, to block traffic for a single IPv4 address, run the following command, where <code>192.168.0.0<\/code> is the IPv4 address that you wish to block:<\/p>\n<pre><code>firewall-cmd --add-rich-rule='rule family=\"ipv4\" source address=\"192.168.0.0\" drop' --permanent\n<\/code><\/pre>\n<p>To block traffic for a single IPv6 address, run the following command, where <code>2001:0db8:0:0:1:0:0:1<\/code> is the IPv6 address that you wish to block:<\/p>\n<pre><code>firewall-cmd --add-rich-rule='rule family=\"ipv6\" source address=\"[2001:0db8:0:0:1:0:0:1]\" drop' --permanent\n<\/code><\/pre>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<p>We recommend that you <strong>only<\/strong> use the firewall utilities on CentOS 7, CloudLinux 7, and RHEL 7 servers.<\/p>\n<ul>\n<li>If you use <code>firewalld<\/code>, you <strong>must<\/strong> enable the daemon before you change the firewall settings. To do this, run the <code>systemctl enable firewalld<\/code> command. If you do not enable the daemon, the system will erase any firewall changes when you reboot the server.<\/li>\n<li>If you use <code>firewalld<\/code>, the system will remove the <code>ipables-services<\/code> package through the yum package manager with the following command: <code>yum remove iptables-service<\/code><\/li>\n<li>If you use the the legacy <code>iptables<\/code> service, remove the <code>firewalld<\/code> package through the yum package manager with the following command: <code>yum remove firewalld<\/code><\/li>\n<li>If you use a third-party firewall management service, we recommend that you check the firewall\u2019s documentation before you remove the unused <code>firewalld<\/code> or <code>iptables<\/code> services.<\/li>\n<\/ul><\/div>\n<\/div>\n<p>For more information about the firewall utilities and the <code>firewalld<\/code> daemon, read Red Hat\u2019s Using Firewalls documentation.<\/p>\n<h4 id=\"the-cpanel-service\">The cpanel service<\/h4>\n<div class=\"callout callout-warning\">\n<div class=\"callout-heading\">Important:<\/div>\n<div class=\"callout-content\">\n<p>The <code>\/usr\/local\/cpanel\/scripts\/configure_firewall_for_cpanel<\/code> script clears all existing entries from the <code>iptables<\/code> application. If you use custom rules for your firewall, export those rules <strong>before<\/strong> you run the script and then re-add them afterward.<\/p>\n<\/p><\/div>\n<\/div>\n<p>cPanel &#038; WHM also includes the <code>cpanel<\/code> service, which manages all of the rules in the <code>\/etc\/firewalld\/services\/cpanel.xml<\/code> file. This allows TCP access for the server\u2019s ports.<\/p>\n<p>To replace your existing <code>iptables<\/code> rules with the rules in the <code>\/etc\/firewalld\/services\/cpanel.xml<\/code> file, perform the following steps:<\/p>\n<ol>\n<li>Run the <code>yum install firewalld<\/code> command to ensure that you have installed the <code>firewalld<\/code> service daemon on your system.<\/li>\n<li>Run the <code>systemctl start firewalld.service<\/code> command to start the <code>firewalld<\/code> service.<\/li>\n<li>Run the <code>systemctl enable firewalld<\/code> command to start the <code>firewalld<\/code> service when the server starts.<\/li>\n<li>Run the <code>iptables-save &gt; backupfile<\/code> command to save your existing firewall rules.<\/li>\n<li>Run the <code>\/usr\/local\/cpanel\/scripts\/configure_firewall_for_cpanel<\/code> script.<\/li>\n<li>Run the <code>iptables-restore &lt; backupfile<\/code> command to incorporate your old firewall rules into the new firewall rules file.<\/li>\n<\/ol>\n<h3 id=\"adding-rules-with-the-iptables-utility\">Adding rules with the iptables utility<\/h3>\n<p>The following examples explain how to add rules with ConfigServer Security &#038; Firewall (CSF), Advanced Policy Firewall (APF), and the <code>iptables<\/code> utility.<\/p>\n<div class=\"callout callout-success\">\n<div class=\"callout-heading\">Remember:<\/div>\n<div class=\"callout-content\">\n<p>Red Hat Enterprise Linux 8 deprecated the <code>iptables<\/code> utility. While cPanel, L.L.C. does not support this version of RHEL, this change affects all cPanel-supported operating systems. We recommend the <code>nftables<\/code> utility for servers that run CentOS 8, AlmaLinux 8, or CloudLinux 8. For servers that run CentOS 7, CloudLinux 7, or RHEL 7, we recommend that you use the <code>firewalld<\/code> utility.<\/p>\n<p>For more information, read Red Hat\u2019s When to use firewalld, nftables, or iptables documentation.<\/p>\n<\/p><\/div>\n<\/div>\n<h4 id=\"configserver-security-firewall\">ConfigServer Security &#038; Firewall<\/h4>\n<p>ConfigServer provides the free WHM plugin ConfigServer Security &#038; Firewall, which allows you to modify your <code>iptables<\/code> rules within WHM. For information about how to install and configure CSF, read our Additional Security Software documentation.<\/p>\n<h4 id=\"advanced-policy-firewall\">Advanced Policy Firewall<\/h4>\n<p>Advanced Policy Firewall (APF) acts as a front-end interface for the <code>iptables<\/code> application, and allows you to open or close ports without the use of the <code>iptables<\/code> syntax.<\/p>\n<p>The following example includes two rules that you can add to the <code>\/etc\/apf\/conf.apf<\/code> file in order to allow HTTP and HTTPS access to your system:<\/p>\n<div class=\"highlight\">\n<div style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\">\n<table style=\"border-spacing:0;padding:0;margin:0;border:0;width:auto;overflow:auto;display:block;\">\n<tr>\n<td style=\"vertical-align:top;padding:0;margin:0;border:0;\">\n<pre style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-PERL\" data-lang=\"PERL\"><span style=\"margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\">1\n<\/span><span style=\"margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\">2\n<\/span><span style=\"margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\">3\n<\/span><\/code><\/pre>\n<\/td>\n<td style=\"vertical-align:top;padding:0;margin:0;border:0;;width:100%\">\n<pre style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-PERL\" data-lang=\"PERL\"><span style=\"color:#75715e\"># Common ingress (inbound) TCP ports<\/span>\nIG_TCP_CPORTS<span style=\"color:#f92672\">=<\/span><span style=\"color:#e6db74\">\"80,443\"<\/span>\nEG_TCP_CPORTS<span style=\"color:#f92672\">=<\/span><span style=\"color:#e6db74\">\"80\"<\/span><\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<\/div>\n<\/div>\n<h4 id=\"iptables\">iptables<\/h4>\n<p>The <code>iptables<\/code> application offers more customization settings for your packet filtering rules. This application requires that you understand the TCP\/IP stack. For more information about the use of <code>iptables<\/code>, visit the iptables site, or run the <code>man iptables<\/code> command from the command line.<\/p>\n<p>The following example includes <code>iptables<\/code> rules for HTTP traffic on port <code>80<\/code>:<\/p>\n<div class=\"highlight\">\n<div style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\">\n<table style=\"border-spacing:0;padding:0;margin:0;border:0;width:auto;overflow:auto;display:block;\">\n<tr>\n<td style=\"vertical-align:top;padding:0;margin:0;border:0;\">\n<pre style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-PERL\" data-lang=\"PERL\"><span style=\"margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\">1\n<\/span><span style=\"margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f\">2\n<\/span><\/code><\/pre>\n<\/td>\n<td style=\"vertical-align:top;padding:0;margin:0;border:0;;width:100%\">\n<pre style=\"color:#f8f8f2;background-color:#272822;-moz-tab-size:4;-o-tab-size:4;tab-size:4\"><code class=\"language-PERL\" data-lang=\"PERL\">$IPTABLES <span style=\"color:#f92672\">-<\/span>A FORWARD <span style=\"color:#f92672\">-<\/span>p TCP <span style=\"color:#f92672\">-<\/span>i <span style=\"color:#ae81ff\">66.66.66.66<\/span> <span style=\"color:#f92672\">-<\/span>o eth0 <span style=\"color:#f92672\">-<\/span>d <span style=\"color:#ae81ff\">192.168.1.1<\/span> <span style=\"color:#f92672\">-<\/span>dport <span style=\"color:#ae81ff\">80<\/span> <span style=\"color:#f92672\">-<\/span>j allowed\n$IPTABLES <span style=\"color:#f92672\">-<\/span>A FORWARD <span style=\"color:#f92672\">-<\/span>p ICMP <span style=\"color:#f92672\">-<\/span>i <span style=\"color:#ae81ff\">66.66.66.66<\/span> <span style=\"color:#f92672\">-<\/span>o eth0 <span style=\"color:#f92672\">-<\/span>d <span style=\"color:#ae81ff\">192.168.1.1<\/span> <span style=\"color:#f92672\">-<\/span>j icmp_packets<\/code><\/pre>\n<\/td>\n<\/tr>\n<\/table>\n<\/div>\n<\/div>\n<div class=\"callout callout-info\">\n<div class=\"callout-heading\">Note:<\/div>\n<div class=\"callout-content\">\n<p>This example assumes that a DMZ exists on <code>eth0<\/code> for the <code>192.168.1.1<\/code> port, and the <code>66.66.66.66<\/code> broadcast IP address.<\/p>\n<\/p><\/div>\n<\/div><\/div>\n","protected":false},"excerpt":{"rendered":"<p>Valid for versions 94 through the latest version Version: 84 86 90 92 94 Overview cPanel &#038; WHM installs and manages many different services on your system, most of which require an external connection in order to function properly. Because of this, your firewall must allow cPanel &#038; WHM to open the ports on which &hellip;<\/p>\n","protected":false},"author":1,"featured_media":679,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts\/678"}],"collection":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/comments?post=678"}],"version-history":[{"count":0,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/posts\/678\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/media\/679"}],"wp:attachment":[{"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/media?parent=678"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/categories?post=678"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ssdsunucum.com\/blog\/wp-json\/wp\/v2\/tags?post=678"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}