Skip to content

Installation guide and quick start

Follow these steps to install cPFence v4+ and prepare your Enhance cluster.

  • Enhance must already be installed on Ubuntu 22.04 or 24.04.
  • Use root and a valid cPFence license for each server.

Already using v3? Follow Migrate from v3.

Sign in to the client area and retrieve your license key and installation command. Choose a billing model if you need a new license.

Start with the main control panel server. Replace YOUR_LICENSE_KEY with your key and run:

Terminal window
bash <(curl -ks https://api.cpfence.app/v4/install.sh) -k YOUR_LICENSE_KEY

A new installation needs the -k key. Without it, the installer stops before changing anything and shows the command to use.

To repair a server that already runs v4, run the installer without a key and choose Back up and reinstall, keeping settings and data:

Terminal window
bash <(curl -ks https://api.cpfence.app/v4/install.sh)

The installer handles setup automatically. Wait for Installation completed successfully. and read its license, protection, update, and configuration notices.

Terminal window
cpfence --status
cpfence --show-stats

Confirm an Active license and review protection status. Fresh installations enable firewall, WAF, website real-time protection, WordPress AutoShield, Owl AutoMySQL, and automatic software updates. Website auto-quarantine and mailbox scanning start off.

To follow current protection logs, use:

Terminal window
cpfence --monitor-ipdb-blocks
cpfence --monitor-owl-logs

Run one stream at a time; Ctrl-C closes it without disabling protection.

Set your notification address on each server:

Terminal window
cpfence --set-email [email protected]

Replace the example address with your own. If mail does not arrive, configure SMTP:

Terminal window
cpfence --enable-cpfence-smtp

cPFence automatically includes the Enhance cluster addresses in the main control panel server’s IPDB allow list. Check the secondary servers too; they do not receive that cluster list automatically.

For a quick list of commands, run this helper on the main control panel server:

Terminal window
bash <(curl -ks https://api.cpfence.app/whitelist_your_ips.sh)

The helper displays addresses and commands; it does not apply them. Review the IPv4 and IPv6 entries, then run the generated cpfence --add-whitelist-ip commands on each secondary server that needs them. Repeat this review when cluster addresses change. For browser-based controls, see IP allow lists.

These controls enable WordPress protection, eligible MySQL query limits, and website monitoring:

Terminal window
cpfence --wp-autoshield-on
cpfence --owl-automysql-on
cpfence --monitorpro-on

WordPress AutoShield and Owl AutoMySQL already default On; MonitorPro defaults Off. Review each server’s role and settings before enabling them. AutoMySQL can terminate eligible long-running queries.

See WordPress protection, Owl AutoMySQL, and MonitorPro for policy, exclusions, and monitoring domains.

Terminal window
cpfence --full-scan

Allow the scan to finish, then inspect results. Large servers can take considerably longer than installation.

8. Configure quarantine and integrity checks

Section titled “8. Configure quarantine and integrity checks”

After reviewing the initial results and keeping recovery backups, enable the recommended actions:

Terminal window
cpfence --enable-quarantine
cpfence --enable-integrity-check
cpfence --enable-auto-file-action
cpfence --set-check-frequency hourly

Auto-quarantine moves detected website malware into quarantine. Integrity monitoring checks WordPress core; automatic file action can quarantine unexpected files and repair eligible core files. Hourly increases the integrity schedule from its daily default. Review exclusions and verify site health after actions. These controls do not enable mailbox quarantine.

On the main control panel server only, with an Active license, run:

Terminal window
cpfence --enable-webui

Follow the password prompts, then open the printed HTTPS address on port 9095. Sign in as admin with your new password. An existing password is retained.

Open Servers. Secondary servers connect automatically after v4 installation. Select Details to check Cluster identity verified and the connection status.

Servers showing a connected secondary server with verified cluster identity.

Connected secondary server details. Names and addresses are blurred for privacy. Select the image to enlarge it; use your browser's Back command to return.

Start with Local in System Settings. Open My account to set up MFA and save recovery codes.

  • License not accepted or inactive: check the key, then run cpfence --install-license cPFence-XXXXXXXXXXXXXXXX, replacing the placeholder with your key from the client area. cPFence stays installed when the installer cannot accept the key. See license activation.
  • Dashboard unavailable: check the printed HTTPS address, port 9095, and approved-IP restrictions before opening a support ticket.
  • Forgot the admin password: run cpfence --reset-webui-pass on the main control panel server.
  • Secondary server unavailable: follow connection troubleshooting.
  • Installation stopped: follow its error. The private log is /var/log/cpfence-v4-install.log.

Continue with System Settings and configuration files. For wider Enhance setup advice, see 20 Tips to Set Up Your Enhance Server Like a Pro.