Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Set Up WAF Rules for Strong Protection

This guide gives a safe, step-by-step way to tune your web application firewall so it blocks attacks but still lets real visitors in.

Firewall2 min read10 steps

What is a WAF?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF looks at each web request to your site and blocks the ones that look like attacks. It follows rules, and each rule describes one type of attack.

Strong does not mean "block everything". Too strict, and good visitors get blocked. Too loose, and attackers get in. The goal is a balance.

Steps

  1. Back up first. Copy your website files and database before you change anything.
  2. Turn the WAF on. Make sure the engine is set to On, not only "Detection only". Detection only just writes logs.
  3. Load a well-known rule set. The OWASP Core Rule Set is free and widely used. It covers common attacks such as SQL injection and cross-site scripting.
  4. Start in detection mode on a busy site. Run for a few days and read the log. This shows which rules would block real visitors.
  5. Fix false positives. A false positive is a good request that the WAF blocks by mistake. Add an exception for that one rule on that one page. Do not turn off whole groups of rules.
  6. Switch to blocking mode. Set the engine to On once the log looks clean.
  7. Raise the strictness slowly. Many rule sets have a level, called paranoia level. A higher level is stricter. Go up one level at a time and test.
  8. Protect the login page. Add a rule or setting to limit repeated login attempts.
  9. Block bad bots and countries you never serve. Only do this if you are sure you do not need that traffic.
  10. Keep rules up to date. Turn on automatic updates if your tool has them.
Warning: After each change, open your site, log in, and submit a form. Test checkout and contact pages too. A rule that breaks them costs you customers.

Where to change settings

  • cPanel: look under Security for ModSecurity, if your plan includes it.
  • Plesk: Tools & Settings, then Web Application Firewall.
  • WHM (VPS or dedicated, root access): search ModSecurity.

Options differ by plan. Ask Hostvento support what is available for you.

Keep watching

  • Read the WAF log once a week.
  • Look for the same IP address hitting you many times.
  • Look for rule IDs that fire often on normal pages.

Need help? Open a support ticket.

Quick recap

  • Back up, then turn the WAF on with a trusted rule set.
  • Test in detection mode, fix false positives, then block.
  • Raise strictness one step at a time.
  • Keep rules updated and read the logs.