What are WAF rules?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads every web request and compares it with a list of rules. Each rule describes one kind of attack. If a request matches, the WAF blocks it.
Attackers invent new tricks all the time. Rule writers publish updated lists. If you never update, your WAF slowly becomes blind to new attacks. Automatic updates fix this.
Option 1: WHM with ModSecurity vendors
This is for VPS and dedicated server customers with root access. WHM is the control panel for the server owner. A vendor is a company or group that publishes a rule set.
- Log in to WHM.
- Search for
ModSecurity Vendorsand open it. - Click Add if you have no vendor yet. Add a trusted rule set, such as OWASP, by using the link WHM shows.
- Find your vendor in the list.
- Switch on Automatic updates (the update toggle) for it.
- Click Update once to fetch the newest rules now.
WHM now checks for new rules on its own.
Option 2: Update by a scheduled job on a server
A cron job is a task the server runs on a timer. You can use one if your rule set comes as a folder you download yourself.
- Connect to the server over SSH as root. SSH is a secure way to type commands on a server.
- Run the command below to open the schedule list.
crontab -e
This opens your list of timed tasks.
- Add a line that runs your update script every night at 3 a.m.:
0 3 * * * /root/update-waf-rules.sh
The script should download the new rules, test the web server settings, and reload the web server. Your support team or the rule vendor can give you an update script.
Option 3: A WAF service
Some WAF services update rules for you in the background. You do nothing. Ask Hostvento support whether your plan can use such a service.
Check that it works
- Look at the date of the last update in the vendor list.
- Watch your WAF log for strange blocks after an update.
Need help? Open a support ticket.
Quick recap
- WAF rules go out of date if not refreshed.
- In WHM, turn on automatic updates for your vendor.
- Or use a cron job with an update script.
- Back up rules and review the logs after updates.