Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Turn ModSecurity On or Off for a Domain in WHM

This guide shows how to use ModSecurity Tools in WHM to control ModSecurity for each domain. It needs root or reseller access to WHM.

Firewall2 min read13 steps11 screenshots

What is ModSecurity?

ModSecurity is a web application firewall. A firewall is a guard that checks traffic. ModSecurity reads each visit to your website and blocks the ones that look like attacks, using a list of rules.

WHM is the control panel for the server owner. A control panel is a website where you manage a server. A VPS or dedicated server customer has root access, which means full control.

Screenshot: WHM is the control panel for the server owner. A control panel is a website where you mana

Why control it per domain?

Sometimes ModSecurity blocks a good action by mistake. This is a "false positive". A page editor or a plugin may stop working on one site. You can switch ModSecurity off for that domain only and keep every other site protected.

Turn ModSecurity on for the server

  1. Log in to WHM.
  2. Type ModSecurity in the search box on the left.
  3. Click ModSecurity Configuration.
    Screenshot: Click ModSecurity Configuration .
  4. Check that Rules Engine is set to On. If it says Off, switch it on and save.
  5. Go back and click ModSecurity Vendors. Add a rule set, such as OWASP, and turn it on. Without rules, ModSecurity has nothing to check for.
    Screenshot: Go back and click ModSecurity Vendors . Add a rule set, such as OWASP, and turn it on. Wit
    Screenshot: Go back and click ModSecurity Vendors . Add a rule set, such as OWASP, and turn it on. Wit
    Screenshot: Go back and click ModSecurity Vendors . Add a rule set, such as OWASP, and turn it on. Wit

The ModSecurity software must be installed on the server first. If you do not see it, check EasyApache 4 in WHM and add ModSecurity there.

Control a single domain

  1. In WHM, open ModSecurity Tools.
  2. Find the domain in the list of domains.
  3. Click the switch in the status column to turn ModSecurity on or off for that domain.
    Screenshot: Click the switch in the status column to turn ModSecurity on or off for that domain.
    Screenshot: Click the switch in the status column to turn ModSecurity on or off for that domain.
  4. Wait a moment. WHM saves the change on its own.

Some newer WHM versions show this as a Domain Manager list or a set of domain options. The names can differ a little between versions, so look for the list of your domains.

Warning: Do not leave a public site with ModSecurity off for long. Switch it off only to test, then turn it back on. Better still, add an exception for the one rule that causes the problem.

Find the cause of a false positive

  1. Try the action that fails again.
  2. Open ModSecurity Tools and look at the Hits List.
    Screenshot: Open ModSecurity Tools and look at the Hits List .
  3. Note the rule ID number.
  4. Add that ID to the list of disabled rules in the configuration, or ask your support team for help.
    Screenshot: Add that ID to the list of disabled rules in the configuration, or ask your support team f

Customers on shared hosting usually cannot reach WHM. For help, open a support ticket.

Quick recap

  • ModSecurity blocks attacks using rules.
  • Turn the rules engine on and add a rule set.
  • Use ModSecurity Tools to switch it per domain.
  • Use the Hits List to find false positives.
    Screenshot: Use the Hits List to find false positives.
    Screenshot: Use the Hits List to find false positives.
  • Do not leave protection off.