Skip to content
Hosting Operations7 min read

cPanel Bandwidth Limit Exceeded AlmaLinux [Solved]

Fix cPanel bandwidth limit exceeded errors on AlmaLinux by identifying traffic sources, blocking bots, and offloading static content to CDNs.

Written by Abdul AbrorTechnical Hosting Support Engineer
man in black and white checkered dress shirt using computer
On this page

TL;DR — Key takeaways

  • Most bandwidth overages come from hotlinked media files, aggressive bot crawlers, or unoptimized video delivery that can be mitigated with referrer checks and CDN offloading.
  • AWStats and cPanel access logs reveal the exact URLs and IP ranges consuming bandwidth, allowing targeted blocks via .htaccess or firewall rules before upgrading hosting plans.
  • AlmaLinux systems benefit from kernel-level traffic shaping with tc commands and iptables rate limiting to prevent single IPs from exhausting account quotas.
  • Setting up Cloudflare or BunnyCDN for static assets typically reduces origin bandwidth by 60-80% without code changes, solving most quota issues permanently.

A cPanel account hitting its bandwidth cap on AlmaLinux usually surfaces as a suspended site and a terse error in WHM. The owner sees the damage after the fact. In support tickets I handled, the usual culprit was a hotlinked image gallery or a PDF someone shared on Reddit that got crawled by every bot on the internet overnight.

AlmaLinux brought no architectural change to how cPanel meters bandwidth compared to CentOS 7, but the migration wave meant thousands of accounts suddenly noticed their traffic patterns when quotas reset. This guide walks through finding the traffic source, applying surgical blocks, and offloading the heavy assets so you stay under quota without upgrading.

Understanding cPanel Bandwidth Limits on AlmaLinux

Bandwidth in cPanel measures total bytes transferred out from your account each month, covering HTTP, HTTPS, FTP, and mail. AlmaLinux runs the same Apache or LiteSpeed web server as prior CentOS builds, so the metering code is identical—WHM's bandwidth module reads access logs and sums the tenth field (bytes sent) per virtual host.

When you exceed the plan limit, cPanel suspends the account and replaces your site with a 509 Bandwidth Limit Exceeded page. The suspension remains until the monthly counter resets or the hosting provider manually lifts it after you upgrade or purchase additional transfer.

Most shared hosting plans cap bandwidth at 50GB to 500GB monthly. A single viral post or hotlinked asset can burn through that in hours. I've seen a 2MB image embedded on a high-traffic forum consume 80GB in a weekend because it loaded on every page view.

    Identifying Traffic Sources in AWStats and Raw Logs

    The first command shows which specific files are moving the most data. The second reveals if a single IP is hammering your server. The third exposes external sites hotlinking your content—if you see a forum domain or image aggregator in the referrer list, someone embedded your asset.

    Cross-reference high-traffic IPs against known bot lists (use 'whois' or an online lookup). Legitimate search engine crawlers obey robots.txt and throttle themselves. Scrapers and content thieves do not.

    • awk '{sum[$7] += $10} END {for (url in sum) print sum[url], url}' access_log | sort -rn | head -20
    • grep '" 200 ' access_log | awk '{print $1}' | sort | uniq -c | sort -rn | head -20 # top IPs by request count
    • awk '{print $11}' access_log | sort | uniq -c | sort -rn | head -10 # top referrers

    Stopping Bot Traffic with User-Agent Blocks

    For AlmaLinux systems with ConfigServer Firewall (CSF) installed, you can block by IP directly in the firewall. Add the offending IP to /etc/csf/csf.deny and restart CSF with 'csf -r'. This stops the traffic at the kernel level before Apache even sees it, saving CPU cycles.

    If the bot rotates IPs across a subnet, block the CIDR range. Find the ASN with 'whois <IP>' and add the entire block to csf.deny if it's a known bad actor. Be careful—blocking too broadly can affect legitimate users on shared hosting or VPNs.

    • RewriteEngine On
    • RewriteCond %{HTTP_USER_AGENT} (MJ12bot|AhrefsBot|SemrushBot|DotBot|BLEXBot) [NC]
    • RewriteRule .* - [F,L]

    Rate Limiting and Traffic Shaping on AlmaLinux

    This limits the /downloads directory to 512KB/sec per connection. A user downloading a file gets smooth throttled delivery instead of saturating the pipe. It's a middle ground between blocking outright and letting traffic run wild.

    • <IfModule mod_ratelimit.c>
    • <Location /downloads>
    • SetOutputFilter RATE_LIMIT
    • SetEnv rate-limit 512
    • </Location>
    • </IfModule>

    Offloading Static Assets to a CDN

    The CDN fetches the file from your origin once, caches it globally, and serves all subsequent requests from the edge. Your cPanel bandwidth meter only counts the initial fetch plus any dynamic or uncached requests. Test by checking the X-Cache header in the CDN response—'HIT' means it's cached, 'MISS' means it fetched from origin.

    • Before: <img src="https://yourdomain.com/images/photo.jpg">
    • After: <img src="https://yourzone.b-cdn.net/images/photo.jpg">

    Monitoring and Alerting for Future Overages

    Parse the JSON output for the current month's bytes. Compare against your plan limit and send an alert via mail or a monitoring service webhook when you cross a threshold. Run this hourly so you notice traffic spikes in near real-time.

    External monitoring tools like UptimeRobot or Hetrix can poll your site and alert on response time changes, which often correlate with bandwidth saturation. If your site slows to a crawl at the same time bandwidth spikes, you've got a traffic attack or a sudden viral hit.

    Document your baseline after optimization. If you normally use 20GB per month and suddenly jump to 150GB, investigate immediately—don't wait for the suspension email. Check AWStats, review new referrers, and look for unusual user-agent strings in the access log.

    • uapi --user=username Bandwidth get_retention_periods_and_accounts_currently_being_processed

    Quick troubleshooting checklist

    • Check current bandwidth usage in cPanel Bandwidth section and note which domains exceed quotas
    • Review AWStats or Raw Access Logs to identify top-requested files and referrer sources
    • Enable hotlink protection in cPanel for image and video directories
    • Block aggressive bot user-agents via .htaccess or CSF firewall rules
    • Configure CDN for static assets (images, CSS, JS, fonts) and update DNS records
    • Set up bandwidth monitoring alerts at 70% and 90% thresholds in WHM or external monitoring
    • Test site functionality after implementing blocks to ensure legitimate traffic is not affected
    • Document baseline bandwidth usage post-optimization for future capacity planning

    FAQ

    What causes cPanel bandwidth limit exceeded errors on AlmaLinux servers?

    Bandwidth overages usually stem from hotlinked media files being embedded on external sites, aggressive search engine or scraper bots making thousands of requests, large video or downloadable files served directly without CDN caching, or DDoS attempts targeting specific endpoints. AlmaLinux handles traffic the same as CentOS, but the error surfaces in cPanel when the account's monthly transfer quota is exhausted, suspending the site until reset or upgraded.

    How do I identify which files are consuming the most bandwidth in cPanel?

    Open AWStats in cPanel and check the Top Files section, which lists URLs by total transfer size. For raw data, download access logs from cPanel Raw Access interface and run 'awk '{print $7, $10}' access_log | sort -k2 -rn | head -20' to see the 20 largest responses by byte count. This reveals if a single PDF, video, or image gallery is responsible for most traffic, allowing targeted caching or access restrictions.

    Can I prevent bandwidth overages without upgrading my cPanel hosting plan?

    Yes, in most cases. Offloading static assets to a CDN like Cloudflare or BunnyCDN removes 60-80% of bandwidth from your origin server. Enabling hotlink protection stops external sites from embedding your images. Blocking bad bots with .htaccess rules or ConfigServer Firewall cuts automated scraper traffic. Compressing images and enabling gzip/brotli reduces file sizes by 50-70%. These changes address the root cause rather than just increasing capacity.