I recently had a situation with my linodes where I got locked out.

They support recommendation from them was to run iptables -F which cleared the problem.
I never found my IPs in csf.deny

My question is, are there 2 layers of firewall.
The rules contained within CSF and additionally on top of that other rules that could have been added by some other process?

Thanks for any insight.
