{"id":3088,"date":"2026-07-12T09:17:09","date_gmt":"2026-07-12T09:17:09","guid":{"rendered":"https:\/\/hostligo.com\/blog\/?p=3088"},"modified":"2026-07-12T09:17:09","modified_gmt":"2026-07-12T09:17:09","slug":"csf-kurulumu-ve-ayarlari","status":"publish","type":"post","link":"https:\/\/hostligo.com\/blog\/csf-kurulumu-ve-ayarlari\/","title":{"rendered":"Linux CSF Kurulumu ve csf.conf Ayarlar\u0131 (2026 G\u00fcncel)"},"content":{"rendered":"<p><strong>CSF (ConfigServer Security &amp; Firewall), Linux i\u015fletim sistemine sahip sunucular i\u00e7in uzun y\u0131llard\u0131r dijital g\u00fcvenli\u011fin vazge\u00e7ilmez yap\u0131 ta\u015flar\u0131ndan biri olmu\u015ftur. Temelinde iptables ile modern nftables mimarilerini bar\u0131nd\u0131ran bu durum denetimli (stateful) g\u00fcvenlik duvar\u0131,<\/strong>CSF mimarisi, yaln\u0131zca root yetkilerine sahip oldu\u011funuz ba\u011f\u0131ms\u0131z bir <a style=\"color: #2563eb; text-decoration: underline;\" href=\"https:\/\/hostligo.com\/vps-server\">VPS sunucu<\/a> ya da fiziksel sunucu altyap\u0131s\u0131nda \u00e7al\u0131\u015ft\u0131r\u0131labilir. Root eri\u015fiminizin bulunmad\u0131\u011f\u0131 payla\u015f\u0131ml\u0131 hosting hesaplar\u0131nda bu t\u00fcr duvarlar do\u011frudan servis sa\u011flay\u0131c\u0131 taraf\u0131ndan merkez\u00ee ve altyap\u0131sal olarak y\u00f6netilmektedir.<\/p>\n<h2 id=\"CSF_Tam_Olarak_Ne_Yapar\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">CSF Tam Olarak Ne Yapar?<\/h2>\n<p style=\"line-height: 1.7; color: #334155;\">CSF klasik bir vir\u00fcs taray\u0131c\u0131 yaz\u0131l\u0131m\u0131 de\u011fildir. O, sunucunuza gelen ve giden a\u011f trafi\u011fini belirli filtreler e\u015fli\u011finde denetleyen, \u015f\u00fcpheli aktiviteleri alg\u0131lay\u0131p defans pozisyonu alan dinamik bir g\u00fcvenlik kalkan\u0131d\u0131r. Sistemdeki ana g\u00f6revleri \u015funlard\u0131r:<\/p>\n<ul style=\"line-height: 1.7; color: #334155; padding-left: 20px;\">\n<li style=\"margin-bottom: 8px;\"><strong>A\u011f Portlar\u0131n\u0131n Kontrol\u00fc:<\/strong> Sunucunun d\u0131\u015f d\u00fcnyaya hangi kap\u0131lar\u0131 a\u00e7aca\u011f\u0131n\u0131 (<code>TCP_IN<\/code>) ve i\u00e7erideki uygulamalar\u0131n d\u0131\u015far\u0131ya hangi kap\u0131lardan eri\u015fece\u011fini (<code>TCP_OUT<\/code>) s\u0131n\u0131rland\u0131r\u0131r. Kapat\u0131lan her gereksiz port, potansiyel bir a\u00e7\u0131\u011f\u0131n kapanmas\u0131 demektir.<\/li>\n<li style=\"margin-bottom: 8px;\"><strong>IP Trafik Y\u00f6netimi:<\/strong> Zararl\u0131 oldu\u011fu kesinle\u015fen IP bloklar\u0131n\u0131 kara listeye al\u0131rken (<code>csf.deny<\/code>), g\u00fcvenli ve kurumsal kaynaklar\u0131 ise beyaz listeye (<code>csf.allow<\/code>) kaydeder.<\/li>\n<li style=\"margin-bottom: 8px;\"><strong>Kaba Kuvvet (Brute-Force) Engelleme:<\/strong> Posta servisleri, SSH hatlar\u0131, FTP kanallar\u0131 veya kontrol panellerine yap\u0131lan hatal\u0131 giri\u015f denemelerini loglar \u00fczerinden anl\u0131k tarayarak sald\u0131rganlar\u0131 kal\u0131c\u0131 ya da ge\u00e7ici olarak sistem d\u0131\u015f\u0131 b\u0131rak\u0131r.<\/li>\n<li style=\"margin-bottom: 0;\"><strong>Geli\u015fmi\u015f Tehdit Savunmas\u0131:<\/strong> SYN flood t\u00fcr\u00fc DDoS giri\u015fimlerine kar\u015f\u0131 defans, port tarama faaliyetlerinin durdurulmas\u0131, co\u011frafi konuma (\u00fclke kodlar\u0131na) g\u00f6re eri\u015fim k\u0131s\u0131tlamas\u0131 ve anl\u0131k e-posta bildirim mekanizmalar\u0131 sa\u011flar.<\/li>\n<\/ul>\n<p style=\"line-height: 1.7; color: #334155; margin-top: 15px;\">T\u00fcm bu operasyonel kararlar <code>\/etc\/csf\/csf.conf<\/code> isimli tek bir merkez\u00ee konfig\u00fcrasyon dosyas\u0131 \u00fczerinden y\u00fcr\u00fct\u00fcl\u00fcr. E\u011fer bir kontrol paneli kullan\u0131yorsan\u0131z, bu dosyadaki parametrelere panelin grafik aray\u00fcz\u00fcnden de m\u00fcdahale edebilirsiniz.<\/p>\n<div id=\"quads-ad7717\" class=\"quads-location quads-ad7717\" style=\"text-align: center; margin: 25px 0; padding: 0;\"><\/div>\n<h2 id=\"Kritik_Degisim_CSF_Guncel_Durumu\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Kritik De\u011fi\u015fim: CSF\u2019in G\u00fcncel Durumu ve 2025-2026 S\u00fcreci<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Sistemin kurulumuna ge\u00e7meden \u00f6nce, projenin mimarisinde ya\u015fanan \u00e7ok \u00f6nemli bir d\u00f6n\u00fc\u015f\u00fcmden bahsetmek gerekir. CSF\u2019in ilk mimar\u0131 olan <strong>Way to the Web Ltd<\/strong>, projeye olan resmi deste\u011fini <strong>31 A\u011fustos 2025<\/strong> tarihi itibar\u0131yla sonland\u0131rd\u0131\u011f\u0131n\u0131 (End-of-Life) duyurdu. Bu hamle nedeniyle eski d\u00f6k\u00fcmanlarda yer alan <code>download.configserver.com<\/code> indirme sunucusu art\u0131k <strong>aktif de\u011fildir<\/strong>. Bu eski adrese ba\u011fl\u0131 kalan sunucular yeni g\u00fcvenlik g\u00fcncellemelerini alamazlar.<\/p>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Ancak a\u00e7\u0131k kaynak d\u00fcnyas\u0131 bu de\u011ferli projeyi sahipsiz b\u0131rakmad\u0131. <strong>cPanel<\/strong>, \u015eubat 2026 d\u00f6neminde hamle yaparak CSF\u2019in resmi \u00e7atallanm\u0131\u015f (fork) versiyonunu GPLv3 lisans modeliyle kendi \u015femsiyesi alt\u0131na ald\u0131. <strong>18 \u015eubat 2026<\/strong>'da cPanel, kendi ekosistemindeki sunucular\u0131n g\u00fcncelleme havuzlar\u0131n\u0131 otomatik olarak cPanel altyap\u0131s\u0131na ba\u011flad\u0131. cPanel haricindeki ba\u011f\u0131ms\u0131z da\u011f\u0131t\u0131mlar i\u00e7in ise topluluk taraf\u0131ndan canl\u0131 tutulan <em>Aetherinox\/csf-firewall<\/em> benzeri alternatif \u00e7atallar kullan\u0131lmaya ba\u015fland\u0131. Mevcut g\u00fcncel s\u00fcr\u00fcm numaras\u0131 <strong>15.10<\/strong> seviyesindedir.<\/p>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 25px;\">\u00d6zetle: CSF mimarisini kullanmaya g\u00fcvenle devam edebilirsiniz; ancak kurulum i\u015flemlerini <strong>do\u011fru ve bak\u0131m\u0131 yap\u0131lan g\u00fcncel kaynaklar<\/strong> \u00fczerinden y\u00fcr\u00fctt\u00fc\u011f\u00fcn\u00fczden emin olmal\u0131s\u0131n\u0131z.<\/p>\n<h2 id=\"Adim_Adim_CSF_Kurulumu\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Ad\u0131m Ad\u0131m CSF Kurulumu (2026 Y\u00f6ntemi)<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Y\u00fckleme i\u015flemlerini ger\u00e7ekle\u015ftirmek i\u00e7in sunucunuza terminal \u00fczerinden root yetkileriyle SSH ba\u011flant\u0131s\u0131 yapman\u0131z gerekir.<\/p>\n<h3 style=\"font-size: 18px; color: #1e293b; margin-top: 20px; margin-bottom: 10px;\">cPanel \/ WHM Entegrasyonlu Sunucular<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 10px;\">cPanel altyap\u0131s\u0131nda en kararl\u0131 y\u00f6ntem, cPanel'in resmi olarak g\u00fcncel tuttu\u011fu da\u011f\u0131t\u0131m\u0131 kullanmakt\u0131r. Yeni nesil cPanel kurulumlar\u0131n\u0131n b\u00fcy\u00fck k\u0131sm\u0131nda bu yap\u0131 haz\u0131rd\u0131r ve y\u00f6nlendirmeler cPanel aynalar\u0131na yap\u0131lm\u0131\u015ft\u0131r. Kontrol etmek veya versiyon y\u00fckseltmek i\u00e7in \u015fu komutlar\u0131 ko\u015fturabilirsiniz:<\/p>\n<pre style=\"background: #0e1b33 !important; color: #e6edf7 !important; padding: 18px; border-radius: 10px; overflow: auto; white-space: pre; line-height: 1.55; font-family: Menlo,Consolas,monospace; font-size: 14px; margin-bottom: 20px;\">csf -v        # Sunucuda aktif olan CSF s\u00fcr\u00fcm bilgisini basar\r\ncsf -u        # G\u00fcvenlik duvar\u0131n\u0131 en yeni s\u00fcr\u00fcme g\u00fcnceller<\/pre>\n<h3 style=\"font-size: 18px; color: #1e293b; margin-top: 25px; margin-bottom: 10px;\">Ba\u011f\u0131ms\u0131z Linux Da\u011f\u0131t\u0131mlar\u0131 (DirectAdmin, Plesk veya Panelsiz Sunucular)<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 10px;\">cPanel d\u0131\u015f\u0131ndaki platformlarda temel mant\u0131k ayn\u0131 kalmakla birlikte <strong>indirme linki<\/strong> g\u00fcncellenmi\u015ftir. Kapanan eski adres yerine, toplulu\u011fun g\u00fcncel tuttu\u011fu aktif repolardan birini se\u00e7melisiniz. A\u015fa\u011f\u0131daki \u015fablonda <code>&lt;guncel-kaynak&gt;<\/code> yazan alana, kulland\u0131\u011f\u0131n\u0131z g\u00fcvenli \u00e7atal\u0131n <code>csf.tgz<\/code> ba\u011flant\u0131s\u0131n\u0131 yerle\u015ftirerek ilerleyin:<\/p>\n<pre style=\"background: #0e1b33 !important; color: #e6edf7 !important; padding: 18px; border-radius: 10px; overflow: auto; white-space: pre; line-height: 1.55; font-family: Menlo,Consolas,monospace; font-size: 14px; margin-bottom: 20px;\">cd \/usr\/src\r\nwget &lt;guncel-kaynak&gt;\/csf.tgz\r\ntar -xzf csf.tgz\r\ncd csf\r\nsh install.sh\r\n\r\n# Gerekli Perl k\u00fct\u00fcphanelerinin kontrol\u00fcn\u00fc sa\u011flay\u0131n\r\nperl \/usr\/local\/csf\/bin\/csftest.pl<\/pre>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">E\u011fer test komutunun ard\u0131ndan ekranda <em>\"RESULT: csf should function on this server\"<\/em> ibaresini g\u00f6rd\u00fcyseniz sistem sorunsuz \u00e7al\u0131\u015facakt\u0131r. Perl mod\u00fcllerinde eksik uyar\u0131s\u0131 gelirse, da\u011f\u0131t\u0131m\u0131n\u0131za uygun paket y\u00f6neticisiyle ilgili ba\u011f\u0131ml\u0131l\u0131klar\u0131 tamamlay\u0131n.<\/p>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 20px;\"><strong>\u00d6nemli Not:<\/strong> Sistemde <code>ufw<\/code> veya <code>firewalld<\/code> gibi ba\u015fka bir aktif g\u00fcvenlik duvar\u0131 y\u00f6neticisi varsa \u00e7ak\u0131\u015fma ya\u015fanmamas\u0131 ad\u0131na bunlar\u0131 kal\u0131c\u0131 olarak kapatmal\u0131s\u0131n\u0131z:<\/p>\n<pre style=\"background: #0e1b33 !important; color: #e6edf7 !important; padding: 18px; border-radius: 10px; overflow: auto; white-space: pre; line-height: 1.55; font-family: Menlo,Consolas,monospace; font-size: 14px; margin-bottom: 25px;\">systemctl stop firewalld\r\nsystemctl disable firewalld<\/pre>\n<h2 id=\"TESTING_Test_Modundan_Cikis\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">TESTING (Test) Modundan \u00c7\u0131k\u0131\u015f<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 10px;\">CSF, sistem y\u00f6neticisinin ilk yap\u0131land\u0131rma esnas\u0131nda ba\u011flant\u0131s\u0131n\u0131n kesilmesini (kendini banlamas\u0131n\u0131) \u00f6nlemek amac\u0131yla varsay\u0131lan olarak <strong>TESTING (Test) modu aktif<\/strong> \u015fekilde kurulur. Bu moddayken arka planda \u00e7al\u0131\u015fan bir cron g\u00f6revi her 5 dakikada bir kurallar\u0131 s\u0131f\u0131rlar. Duvar\u0131n ger\u00e7ek koruma sa\u011flamaya ba\u015flamas\u0131 i\u00e7in <code>\/etc\/csf\/csf.conf<\/code> dosyas\u0131n\u0131 a\u00e7\u0131p ilgili sat\u0131r\u0131 \u015fu hale getirin:<\/p>\n<pre style=\"background: #0e1b33 !important; color: #e6edf7 !important; padding: 18px; border-radius: 10px; overflow: auto; white-space: pre; line-height: 1.55; font-family: Menlo,Consolas,monospace; font-size: 14px; margin-bottom: 15px;\">TESTING = \"0\"<\/pre>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 10px;\">Dosyay\u0131 kaydedip \u00e7\u0131kt\u0131ktan sonra g\u00fcvenlik duvar\u0131n\u0131 devreye al\u0131n ve kurallar\u0131 sisteme i\u015fletin:<\/p>\n<pre style=\"background: #0e1b33 !important; color: #e6edf7 !important; padding: 18px; border-radius: 10px; overflow: auto; white-space: pre; line-height: 1.55; font-family: Menlo,Consolas,monospace; font-size: 14px; margin-bottom: 25px;\">csf -e        # G\u00fcvenlik duvar\u0131n\u0131 aktif konuma getirir\r\ncsf -r        # Mevcut kurallar\u0131 ve konfig\u00fcrasyonu yeniden y\u00fckler<\/pre>\n<h2 id=\"Stratejik_csfconf_Yapilandirmasi\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Stratejik csf.conf Yap\u0131land\u0131rmas\u0131<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Sistem g\u00fcvenli\u011finin anahtar\u0131 do\u011fru yap\u0131land\u0131rmad\u0131r. Sunucunun amac\u0131na uygun port k\u0131s\u0131tlamalar\u0131 yapmak, sald\u0131r\u0131 y\u00fczeyini minimuma indirir ve maksimum g\u00fcvenlik ilkesini destekler.<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 20px;\">\n<table style=\"width: 100%; border-collapse: collapse; text-align: left; font-size: 14px; color: #334155;\">\n<thead>\n<tr style=\"background: #f1f5f9; border-bottom: 2px solid #cbd5e1;\">\n<th style=\"padding: 12px; font-weight: bold; color: #1e293b;\">De\u011fi\u015fken Ad\u0131<\/th>\n<th style=\"padding: 12px; font-weight: bold; color: #1e293b;\">\u00d6nerilen De\u011fer<\/th>\n<th style=\"padding: 12px; font-weight: bold; color: #1e293b;\">A\u00e7\u0131klama ve G\u00f6revi<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">TESTING<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"0\"<\/td>\n<td style=\"padding: 12px;\">\"1\" de\u011feri testi ifade eder. Ayarlar\u0131n\u0131z bitti\u011finde korumay\u0131 ba\u015flatmak i\u00e7in \"0\" yap\u0131n.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">TCP_IN<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"22,80,443\"<\/td>\n<td style=\"padding: 12px;\">D\u0131\u015far\u0131dan sunucuya do\u011fru gelecek isteklere a\u00e7\u0131k portlar (Standart web sunucu \u00f6rne\u011fi).<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">TCP_OUT<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"53,80,443\"<\/td>\n<td style=\"padding: 12px;\">Sunucunun d\u0131\u015f d\u00fcnyadaki sunuculara eri\u015firken kullanaca\u011f\u0131 port s\u0131n\u0131r\u0131.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">LF_SSHD<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"5\"<\/td>\n<td style=\"padding: 12px;\">Belirtilen say\u0131da hatal\u0131 SSH denemesi yapan kayna\u011f\u0131 bloklar.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">LF_SSHD_PERM<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"1\"<\/td>\n<td style=\"padding: 12px;\">SSH \u00fczerindeki kaba kuvvet taramalar\u0131nda engellemenin kal\u0131c\u0131 olmas\u0131n\u0131 sa\u011flar.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">SYNFLOOD<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"1\"<\/td>\n<td style=\"padding: 12px;\">Olas\u0131 ani SYN flood ak\u0131nlar\u0131na kar\u015f\u0131 koruma filtresini a\u00e7ar (Trafi\u011fe g\u00f6re optimize edilmeli).<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">CT_LIMIT<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"100\"<\/td>\n<td style=\"padding: 12px;\">Tek bir IP adresinden sunucuya e\u015fzamanl\u0131 yap\u0131labilecek maksimum ba\u011flant\u0131 s\u0131n\u0131r\u0131.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold;\">CC_DENY \/ CC_ALLOW<\/td>\n<td style=\"padding: 12px; font-family: monospace;\">\"CN,RU\"<\/td>\n<td style=\"padding: 12px;\">Co\u011frafi konum kodlar\u0131 kullanarak belirli \u00fclkelere eri\u015fim k\u0131s\u0131tlamas\u0131 getirir.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 25px;\">E\u011fer sunucunuzda aktif bir <a style=\"color: #2563eb; text-decoration: underline;\" href=\"https:\/\/hostligo.com\/hosting\/email-hosting\">kurumsal mail hosting<\/a> yap\u0131s\u0131 bar\u0131nd\u0131racaksan\u0131z, <code>TCP_IN<\/code> havuzuna e-posta protokollerinin portlar\u0131n\u0131 da (\u00f6rne\u011fin <code>25, 465, 587, 993, 995<\/code>) dahil etmeniz \u015fartt\u0131r. Benzer \u015fekilde FTP s\u00fcre\u00e7leri i\u00e7in pasif port aral\u0131klar\u0131n\u0131 (\u00f6rn: <code>30000:35000<\/code>) hem FTP servis ayarlar\u0131n\u0131zda hem de CSF port listesinde e\u015flemelisiniz.<\/p>\n<h2 id=\"Elinizin_Altinda_Bulunmasi_Gereken_Komutlar\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Elinizin Alt\u0131nda Bulunmas\u0131 Gereken CSF Komutlar\u0131<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Sunucuyu terminalden y\u00f6netirken en s\u0131k ihtiya\u00e7 duyaca\u011f\u0131n\u0131z pratik komutlar ve g\u00f6revleri \u015fu \u015fekildedir:<\/p>\n<div style=\"overflow-x: auto; margin-bottom: 25px;\">\n<table style=\"width: 100%; border-collapse: collapse; text-align: left; font-size: 14px; color: #334155;\">\n<thead>\n<tr style=\"background: #f1f5f9; border-bottom: 2px solid #cbd5e1;\">\n<th style=\"padding: 12px; font-weight: bold; color: #1e293b; width: 40%;\">Terminal Komutu<\/th>\n<th style=\"padding: 12px; font-weight: bold; color: #1e293b; width: 60%;\">A\u00e7\u0131klama ve G\u00f6revi<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -a 1.2.3.4 [ofis]<\/td>\n<td style=\"padding: 12px;\">Belirtilen IP'yi kal\u0131c\u0131 olarak g\u00fcvenli izin listesine (<code>csf.allow<\/code>) ekler.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -d 1.2.3.4 [saldirgan]<\/td>\n<td style=\"padding: 12px;\">\u015e\u00fcpheli veya zararl\u0131 IP'yi kal\u0131c\u0131 kara listeye (<code>csf.deny<\/code>) g\u00f6nderir.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -tr 1.2.3.4<\/td>\n<td style=\"padding: 12px;\">\u0130lgili IP \u00fczerindeki t\u00fcm ge\u00e7ici engelleme veya izin kararlar\u0131n\u0131 kald\u0131r\u0131r.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -g 1.2.3.4<\/td>\n<td style=\"padding: 12px;\">Bu IP adresine duvar \u00fczerinde uygulanan aktif kurallar\u0131 sorgular (Sorun \u00e7\u00f6z\u00fcm\u00fc).<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -ta 1.2.3.4 3600<\/td>\n<td style=\"padding: 12px;\">Belirlenen IP'ye saniye cinsinden (\u00f6rnekte 1 saat) ge\u00e7ici izin tan\u0131mlar.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -td 1.2.3.4<\/td>\n<td style=\"padding: 12px;\">\u015e\u00fcpheli adresi ge\u00e7ici s\u00fcreyle bloklar.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -r<\/td>\n<td style=\"padding: 12px;\">Konfig\u00fcrasyon de\u011fi\u015fikliklerinin ard\u0131ndan t\u00fcm kurallar\u0131 ve sistemi yeniden ba\u015flat\u0131r.<\/td>\n<\/tr>\n<tr style=\"border-bottom: 1px solid #e2e8f0; background: #f8fafc;\">\n<td style=\"padding: 12px; font-family: monospace; font-weight: bold; color: #0f172a;\">csf -x \/ csf -e<\/td>\n<td style=\"padding: 12px;\">G\u00fcvenlik duvar\u0131n\u0131 tamamen devre d\u0131\u015f\u0131 b\u0131rak\u0131r \/ yeniden aktif konuma getirir.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/div>\n<h2 id=\"Yapilandirma_Esnasinda_Dikkat_Edilmesi_Gerekenler\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Yap\u0131land\u0131rma Esnas\u0131nda Dikkat Edilmesi Gerekenler<\/h2>\n<ul style=\"line-height: 1.7; color: #334155; padding-left: 20px;\">\n<li style=\"margin-bottom: 10px;\"><strong>Eri\u015fiminizi G\u00fcvenceye Al\u0131n:<\/strong> <code>TESTING = \"0\"<\/code> yapmadan evvel, SSH servisinizin kulland\u0131\u011f\u0131 port numaras\u0131n\u0131n <code>TCP_IN<\/code> havuzunda tan\u0131ml\u0131 oldu\u011fundan kesinlikle emin olun; aksi halde sunucunun d\u0131\u015f\u0131nda kal\u0131r, eri\u015fiminizi kaybedersiniz.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>Yedek Oturum Hayat Kurtar\u0131r:<\/strong> Ayarlar\u0131 uygularken halihaz\u0131rda ba\u011fl\u0131 oldu\u011funuz SSH ekran\u0131n\u0131 kapatmay\u0131n. Yeni ve ba\u011f\u0131ms\u0131z bir terminal penceresi a\u00e7arak ba\u011flant\u0131n\u0131n sa\u011fl\u0131kl\u0131 kurulup kurulmad\u0131\u011f\u0131n\u0131 test edin.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>Y\u00f6netici IP'sini Sabitleyin:<\/strong> E\u011fer statik (sabit) bir ofis veya ev IP adresiniz varsa, bu adresi hem <code>csf.allow<\/code> hem de <code>csf.ignore<\/code> listelerine i\u015fleyin ki LFD mekanizmas\u0131 yanl\u0131\u015fl\u0131kla kendi eri\u015fiminizi engellemesin.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>Tek G\u00fcvenlik Duvar\u0131 Kural\u0131:<\/strong> Da\u011f\u0131t\u0131m \u00fczerinde yer alan <code>firewalld<\/code> veya <code>ufw<\/code> gibi di\u011fer \u00e7ak\u0131\u015fabilecek a\u011f y\u00f6neticilerini tamamen durdurun.<\/li>\n<li style=\"margin-bottom: 10px;\"><strong>G\u00fcncel Repolar\u0131 Takip Edin:<\/strong> Kapanm\u0131\u015f olan eski <code>download.configserver.com<\/code> adresini referans almay\u0131n; cPanel altyap\u0131s\u0131 veya topluluk taraf\u0131ndan bak\u0131m\u0131 s\u00fcren aktif \u00e7atallar\u0131 kullan\u0131n.<\/li>\n<li style=\"margin-bottom: 0;\"><strong>SSH Yap\u0131s\u0131n\u0131 G\u00fc\u00e7lendirin:<\/strong> Sunucunun varsay\u0131lan SSH portunu (22) daha y\u00fcksek ve rastgele bir de\u011fere \u00e7ekip bu de\u011feri CSF'e i\u015flemek, otomatik bot taramalar\u0131n\u0131n \u00e7ok b\u00fcy\u00fck bir k\u0131sm\u0131n\u0131 ba\u015ftan bertaraf eder.<\/li>\n<\/ul>\n<h2 id=\"Katmanli_Guvenlik_Yaklasimi\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 15px;\">Katmanl\u0131 G\u00fcvenlik Yakla\u015f\u0131m\u0131: CSF Tek Ba\u015f\u0131na Yeterli mi?<\/h2>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">CSF, a\u011f katman\u0131nda harika i\u015fler \u00e7\u0131karan g\u00fc\u00e7l\u00fc bir muhaf\u0131zd\u0131r ancak modern siber tehditler tek boyutlu de\u011fildir. Tam zamanl\u0131 bir koruma; a\u011f duvar\u0131, uygulama seviyesi korumalar (WAF), zararl\u0131 yaz\u0131l\u0131m taray\u0131c\u0131lar\u0131 ve DDoS \u00f6nleme sistemlerinin entegre \u00e7al\u0131\u015fmas\u0131yla m\u00fcmk\u00fcnd\u00fcr. A\u011f g\u00fcvenli\u011fini tek bir araca y\u00fcklemek yerine \u00e7ok katmanl\u0131 savunma stratejisi kurgulamak gerekir. Bu sebeple do\u011fru yap\u0131land\u0131r\u0131lm\u0131\u015f bir CSF filtresini; uygulama katman\u0131nda \u00e7al\u0131\u015fan bir malware taray\u0131c\u0131 ve a\u011f d\u00fczeyinde \u00e7al\u0131\u015fan anti-DDoS \u00e7\u00f6z\u00fcm\u00fcyle birle\u015ftirmek en rasyonel yakla\u015f\u0131md\u0131r.<\/p>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 25px;\">Nitekim profesyonel bir <a style=\"color: #2563eb; text-decoration: underline;\" href=\"https:\/\/hostligo.com\/vps-server\">Hostligo sunucu<\/a> ve bulut sunucu altyap\u0131s\u0131nda y\u00f6netim s\u00fcre\u00e7leri bu katmanl\u0131 mimari \u00fczerine in\u015fa edilir. Sunucu taraf\u0131nda konumlanan Imunify360 mimarisi, yapay zekayla beslenen anl\u0131k tehdit analitikleri, ak\u0131ll\u0131 WAF yap\u0131lar\u0131 ve y\u00fcksek kapasiteli L3-L4 a\u011f seviyesi anti-DDoS filtreleri projelerin kesintisiz \u00e7al\u0131\u015fmas\u0131n\u0131 garanti alt\u0131na al\u0131r. K\u0131sacas\u0131; i\u015fletim sistemi d\u00fczeyinde CSF gibi mekanizmalar\u0131 kendiniz optimize edebilece\u011finiz gibi, altyap\u0131n\u0131n y\u00fcksek g\u00fcvenlik standartlar\u0131n\u0131 do\u011frudan Hostligo'nun uzman ekibine ve yedekli veri merkezi mimarisine de g\u00fcvenle emanet edebilirsiniz.<\/p>\n<h2 id=\"Sikca_Akla_Gelen_Sorular\" style=\"font-size: 22px; color: #1e293b; border-bottom: 2px solid #e2e8f0; padding-bottom: 8px; margin-top: 35px; margin-bottom: 20px;\">S\u0131k\u00e7a Sorulan Sorular<\/h2>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">CSF sistemi tamamen \u00fccretsiz mi?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Evet, tamamen a\u00e7\u0131k kaynak kodlu ve \u00fccretsiz bir yaz\u0131l\u0131md\u0131r. cPanel\/WHM, DirectAdmin ve Plesk panelleriyle entegre \u00e7al\u0131\u015fabilir. Kullan\u0131m\u0131 i\u00e7in herhangi bir lisans \u00fccreti talep edilmez; kurulum i\u00e7in yaln\u0131zca root yetkili bir sunucu gereklidir.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">CSF projesi kapat\u0131ld\u0131 m\u0131, hala kullan\u0131labilir mi?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Orijinal geli\u015ftirici firma projeyi 31 A\u011fustos 2025'te sonland\u0131rd\u0131 ancak proje \u00f6lmedi. cPanel ekibi resmi olarak projenin y\u00f6netimini \u00fcstlendi ve GPLv3 lisans\u0131yla g\u00fcncel tutuyor. Do\u011fru indirme kaynaklar\u0131n\u0131 kulland\u0131\u011f\u0131n\u0131z s\u00fcrece sunucunuzda emniyetle bar\u0131nd\u0131rabilirsiniz.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">Eski download.configserver.com indirme linki neden \u00e7al\u0131\u015fm\u0131yor?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Projenin eski sahiplerine ait olan bu sunucu altyap\u0131s\u0131, faaliyetlerin durdurulmas\u0131yla kapat\u0131ld\u0131. cPanel tabanl\u0131 sunucularda sistem g\u00fcncellemeleri otomatik olarak cPanel altyap\u0131s\u0131na y\u00f6nlendirilirken, panelsiz sistemlerde topluluk taraf\u0131ndan bak\u0131m\u0131 \u00fcstlenilen yeni \u00e7atallar\u0131n (fork) g\u00fcncel ba\u011flant\u0131 adresleri kullan\u0131lmal\u0131d\u0131r.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">Sunucuya eri\u015fimim engellendi (Kendimi kilitledim), ne yapmal\u0131y\u0131m?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Hizmet ald\u0131\u011f\u0131n\u0131z firman\u0131n paneli \u00fczerinden sunulan VNC, IP-KVM veya kurtarma modu (Rescue Mode) konsolu ile sunucu terminaline ula\u015f\u0131p <code>csf -x<\/code> komutunu \u00e7al\u0131\u015ft\u0131rarak duvar\u0131 ge\u00e7ici olarak devre d\u0131\u015f\u0131 b\u0131rakabilir ve hatan\u0131z\u0131 d\u00fczeltebilirsiniz. Bu y\u00fczden kuruluma ba\u015flamadan \u00f6nce konsol eri\u015fiminizi kontrol etmeniz \u00f6nerilir.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">Fail2ban ile CSF ayn\u0131 anda \u00e7al\u0131\u015ft\u0131r\u0131labilir mi?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">\u00c7al\u0131\u015ft\u0131r\u0131lmas\u0131 tavsiye edilmez. CSF i\u00e7erisindeki LFD mod\u00fcl\u00fc, Fail2ban yaz\u0131l\u0131m\u0131n\u0131n yapt\u0131\u011f\u0131 i\u015fin ayn\u0131s\u0131n\u0131 daha optimize \u015fekilde ger\u00e7ekle\u015ftirir. \u0130ki servis sisteminin ayn\u0131 anda log taramas\u0131 yap\u0131p kural girmesi iptables\/nftables \u00fczerinde \u00e7ak\u0131\u015fmalara ve tutars\u0131zl\u0131klara yol a\u00e7ar.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">CSF cPanel\/WHM paneli \u00fczerinden y\u00f6netilebilir mi?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Evet, WHM aray\u00fcz\u00fcnde bulunan \"ConfigServer Security &amp; Firewall\" eklentisi sayesinde t\u00fcm ayarlar\u0131, banlanan IP listelerini ve port kurallar\u0131n\u0131 grafik aray\u00fcz (GUI) \u00fczerinden kolayca y\u00f6netebilirsiniz.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">CSF mimarisi iptables yerine nftables kullanabilir mi?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Evet. Modern Linux da\u011f\u0131t\u0131mlar\u0131 varsay\u0131lan olarak nftables yap\u0131s\u0131na ge\u00e7ti\u011fi i\u00e7in CSF'in yeni s\u00fcr\u00fcmleri nftables mimarisiyle tam uyumludur. Altyap\u0131da kurallar otomatik i\u015flenir, son kullan\u0131c\u0131 y\u00f6netim mant\u0131\u011f\u0131 de\u011fi\u015fmez.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">\u00dclke bazl\u0131 engellemeler sunucuyu yorar m\u0131?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 15px;\">Evet. <code>CC_DENY<\/code> veya <code>CC_ALLOW<\/code> ile geni\u015f co\u011frafi b\u00f6lgeleri engelledi\u011finizde, sisteme devasa IP listeleri y\u00fcklenir. Bu durum \u00f6zellikle ram ve i\u015flemci kaynaklar\u0131 k\u0131s\u0131tl\u0131 olan k\u00fc\u00e7\u00fck \u00f6l\u00e7ekli sanal sunucularda performans kayb\u0131na yol a\u00e7abilece\u011fi i\u00e7in dikkatli kullan\u0131lmal\u0131d\u0131r.<\/p>\n<h3 style=\"font-size: 16px; color: #1e293b; margin-top: 15px; margin-bottom: 5px;\">Bir web sunucusunda hangi portlar\u0131 a\u00e7\u0131k b\u0131rakmal\u0131y\u0131m?<\/h3>\n<p style=\"line-height: 1.7; color: #334155; margin-bottom: 0;\">Sade ve standart bir web sunucusu i\u00e7in giri\u015f y\u00f6n\u00fcnde (<code>TCP_IN<\/code>) 22 (SSH), 80 (HTTP) ve 443 (HTTPS) portlar\u0131n\u0131n a\u00e7\u0131k olmas\u0131 yeterlidir. Aktif olarak mail sunucusu veya FTP protokol\u00fc bar\u0131nd\u0131rm\u0131yorsan\u0131z di\u011fer t\u00fcm portlar\u0131 kapal\u0131 tutarak sald\u0131r\u0131 y\u00fczeyinizi daraltman\u0131z g\u00fcvenli\u011finiz i\u00e7in kritik \u00f6neme sahiptir.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CSF (ConfigServer Security &amp; Firewall), Linux i\u015fletim sistemine sahip sunucular i\u00e7in uzun y\u0131llard\u0131r dijital g\u00fcvenli\u011fin vazge\u00e7ilmez yap\u0131 ta\u015flar\u0131ndan biri olmu\u015ftur. Temelinde iptables ile modern nftables mimarilerini bar\u0131nd\u0131ran bu durum denetimli (stateful) g\u00fcvenlik duvar\u0131,CSF mimarisi, yaln\u0131zca root yetkilerine sahip oldu\u011funuz ba\u011f\u0131ms\u0131z bir VPS sunucu ya da fiziksel sunucu altyap\u0131s\u0131nda \u00e7al\u0131\u015ft\u0131r\u0131labilir. Root eri\u015fiminizin bulunmad\u0131\u011f\u0131 payla\u015f\u0131ml\u0131 hosting hesaplar\u0131nda [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":3091,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"pagelayer_contact_templates":[],"_pagelayer_content":"","footnotes":""},"categories":[1],"tags":[281,277,276,278,280,279],"class_list":["post-3088","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ipuclari","tag-cpanel-csf-firewall","tag-csf-kurulumu","tag-csf-nedir","tag-csf-conf-ayarlari","tag-lfd-brute-force-engelleme","tag-linux-guvenlik-duvari"],"_links":{"self":[{"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/posts\/3088","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/comments?post=3088"}],"version-history":[{"count":1,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/posts\/3088\/revisions"}],"predecessor-version":[{"id":3092,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/posts\/3088\/revisions\/3092"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/media\/3091"}],"wp:attachment":[{"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/media?parent=3088"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/categories?post=3088"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/hostligo.com\/blog\/wp-json\/wp\/v2\/tags?post=3088"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}