cPFence v4 public beta is here.

Explore v4

Support / FAQ

Frequently asked questions

Find answers about cPFence installation, protection, licensing, and Enhance control panel support.

Who is behind cPFence, and is it safe to use?

cPFence was created by our hosting and software development company, Linkers Gate LLC (Linkers Technology). Our company is registered with Company Number: 105300800219093, VAT: 752-267-353, and Dun & Bradstreet under D-U-N-S Number 561227945. We are a small team of six talented server admins and developers. We originally developed cPFence for our own use, and it has served us exceptionally well, to the point where we install it by default on all our clients’ servers. To protect the software, we wrapped it in a license-based system, and we’ve decided to offer it to the public.

How does v4+ work?
cPFence v4+ uses our native malware scanner for website and server files, with ClamAV used for email scanning only. Its browser-based WebUI brings protection settings, scan results and recovery tools together across your Enhance cluster. You choose the server scope and enabled protections, then review their results. See the v4+ guides for installation, settings and recovery.

Why Does cPFence Only Support Enhance Panel?

Because it was already developed and ready to use! cPFence was initially built for our own use across all servers in our hosting and server management company. Since we exclusively use the Enhance control panel and find it perfectly aligned with our business model, cPFence was specifically designed to support it.

cPFence v4+ supports Enhance on Ubuntu 22.04 and 24.04.

Has cPFence been tested for the Mail Server, Database, and Main Control Panel roles?

cPFence v4+ is built for the different roles in your Enhance cluster, including the main control panel server, secondary application and database servers, and mail servers. Website and server-file scans use the native cPFence scanner; ClamAV is used for email scanning only. Mailbox scanning and email quarantine have separate settings, so enable and review the protections you need on each server. See the email-scanning guide.

When will UI integration be available for cPFence in the Enhance control panel?

cPFence v4+ offers a unified browser-based dashboard that gives you more power and control than what would be possible inside the Enhance panel itself.
All your servers can be managed from one place, with advanced tools that go beyond single-server control. For this reason, we’re not planning to integrate cPFence directly into the Enhance UI. The new central dashboard is the recommended way forward. Learn More Here.

How do the Owl and virus detection features work in cPFence?

Owl watches CPU, memory, disk, I/O and inode usage and sends resource alerts through your configured notification channels. Owl WatchDog also checks eligible enabled services and can attempt recovery when a service fails. Set resource alerts and watchdog timing.

Owl AutoMySQL handles eligible long-running queries according to your settings and exclusions. Review the affected accounts before changing limits. Learn about AutoMySQL.

Malware protection is separate: cPFence v4+ checks changed website files every five minutes when scans and resources permit, using the native scanner and cPFence signatures. Detections appear in scan results; when auto-quarantine is enabled, detected website files are moved into quarantine for review and recovery. Manage real-time protection.

Why are so many IPs blocked by cPFence Protection?

The IPs you’re seeing in the list are primarily from bots and scanners that are constantly probing the internet for vulnerabilities, scanning ports, and generally doing harmful activities. Unfortunately, the internet is filled with these malicious IPs these days.

cPFence maintains a comprehensive IP database (IPDB) that includes known spammers, scanners, and hacker IPs. We block these IPs at the network level before they can even reach your server. This proactive protection helps keep your server secure and reduces unnecessary resource usage.

In the WebUI, choose the affected server and open IPDB Firewall & IP Tools to review incidents and current policy. Historical counts do not prove that an IP is still blocked.

To follow current blocks from a root terminal, use cpfence --monitor-ipdb-blocks. Press Ctrl+C to leave the log view without disabling protection. See IPDB and firewall controls.

How does cPFence WAF work compared to competitors?

cPFence combines request-level WAF rules with Layer7, Bot and CAPTCHA controls, alongside shared IPDB protection. Layer7 can identify and block abusive client IPs behind supported proxies, while the WebUI lets you review blocked requests and manage rules for the affected domain.

Apache, Nginx, OpenLiteSpeed and LiteSpeed have different engine limits; protection depends on the request type and your settings. See WAF controls and engine limits before changing a rule or excluding a domain.

How do I install cPFence?

First, choose your license and retrieve its key from the client area. Follow the v4+ installation and quick-start guide: install on the main control panel server, then on every secondary server. The guide includes the installer commands, hosting-provider firewall rules, notifications and your first scan.

Already using v3? Use the migration guide to retain your existing choices.

Can I move my license to a new server?

Yes. For an individual per-server license, use Reissue in the client area, install the key on the new server and check that its license is Active. Bulk licenses use support-managed IP changes; per-website licenses synchronize the cluster IP list instead. Follow the steps for your license type.

Do you offer Bulk licenses ?

Yes, we offer bulk licenses for 10+ servers. Please order your bulk license through this link. Ensure you provide the full list of your server IPs so we can manually activate them under one license key. Bulk licenses do not have automatic activation and will be activated asap upon receiving payment. Single server licenses do have automatic activation.

For changes to an existing bulk license, ask support to update its IP list; do not use the individual-license Reissue action.

How does per-website pricing work, and can I switch to per-server pricing?

With per-website pricing, cPFence charges $0.10 per website per month across all servers in your cluster (you can secure all your servers for as little as $5!). This includes all server types, such as CP, Mail, Backup, and App+DB, with a minimum fee of $5 that covers up to 50 websites.

For example:

  • 50 websites or fewer: $5 per month for complete cluster coverage.
  • 100 websites: $10 per month for complete cluster coverage.

With the per-server billing model, having 4 servers (CP, Mail, Backup, App+DB) would cost $20 per month, calculated as 4 x $5. However, with per-website pricing, the same setup would only cost $5 for all your servers with up to 50 websites. We recommend choosing the per-website model if your website count is low, as it’s often the more economical choice for smaller clusters.

You can switch to per-server pricing anytime, paying $5 per server monthly with unlimited websites, which may offer more savings as your cluster grows.

Per-website billing has no free trial: activation generates an invoice immediately.

To get started with per-website billing, please follow the instructions in this link: How to Activate Per Website Pricing on My Account.

How does your DDos protection work?

cPFence DDoS connection protection checks concurrent connections per source. The default limit is 100; you can adjust Connection limit for the selected server in System Settings. The IPDB page also provides protection switches and temporary Under-Attack Mode.

Many GET requests can be normal, and traffic behind a proxy needs separate consideration. Review site logs, current IP policy and service health before blocking a source. Configure IPDB and DDoS protection or check whether traffic is an attack.

Does cPFence v4+ need passwordless SSH between servers?

Ordinary cPFence v4+ cluster features do not need passwordless SSH. Secondary servers use the native cluster connection instead. Only MultiRun and remote WordPress backups and restores require passwordless SSH access. If you do not use either feature, you can disable that inter-server SSH access and keep the other v4+ features working normally.

Follow the installation guide for cluster access and provider-firewall requirements, or the WordPress backup guide for the remote-backup prerequisite.