If you installed CSF, (Config Server Firewall), on the server, there is a daemon called Login Failure Daemon (lfd), bundled with CSF, which is a process that runs all the time and periodically (every X seconds) scans the latest log file entries for login attempts against your server that continually fail within a short period of time.
Normally called "Brute-force attacks" the daemon process responds quickly to such patterns and blocks the IP's.
To check why 'lfd' has failed look at the end of /var/log/lfd.log
Support for csf + lfd is at:
If an error while trying to start 'csf' check/reconfigure ip tables, 'lfd' should start normally.