When administering remote Linux production servers protected by ConfigServer Security & Firewall (CSF), dynamic residential IPs frequently get blocked or locked out of management portals. Here is a lightweight, automated mechanism to dynamically whitelist your current IP address simply by visiting a private URL on your server.
Architecture: PHP capture endpoint • Fast-polling background Bash daemon • CSF Perl reload
1. The PHP Endpoint (whatis.php)
Create a secure PHP script in your web root that logs the visitor's remote client IP to a temporary staging file:
<?php
// Protect with an authentication token or secret parameter in production
file_put_contents("/tmp/iplog", $_SERVER["REMOTE_ADDR"]);
echo "IP captured: " . htmlspecialchars($_SERVER["REMOTE_ADDR"]);
?>
2. The Shell Whitelister Daemon (/script/ip)
Create a root shell script to inspect the staging file, update /etc/csf/csf.allow, and reload firewall rules:
#!/bin/bash
i=1
while [ $i -le 10 ]
do
status=$(cat /tmp/iplog 2>/dev/null)
if [ -n "$status" ] && [ "$status" != "0" ]; then
echo "$status" >> /etc/csf/csf.allow
echo "$status" >> /etc/csf/csf.ignore
echo "0" > /tmp/iplog
# Note: Use csf.pl -r inside scripts for reliable Perl-based reload
/etc/csf/csf.pl -r > /tmp/csf.log 2>&1
fi
sleep 5
(( i++ ))
done
Make the script executable:
chmod +x /script/ip
3. Cronjob Schedule
Add a root crontab entry to execute the daemon once every minute:
* * * * * /script/ip
Implementation Tip: Calling csf -r from non-interactive shell scripts often fails to reload properly. Invoking the underlying Perl script /etc/csf/csf.pl -r ensures firewall tables reload reliably.