Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Turn Off a WAF for a Short Time Safely

Sometimes the firewall blocks something you need. This guide shows how to pause it in the safest way, and how to turn it back on.

Firewall2 min read15 steps

What is a WAF?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF protects your website by blocking requests that look like attacks.

It can make mistakes. It may block a page builder, a payment callback or a plugin update. This is called a false positive: a good action treated as bad. Then you may want to pause the WAF to see if it is the cause.

Warning: A site with no WAF is easier to attack. Keep the pause short. Take a backup of your site before you start.

Safer choices first

Do not switch everything off if a smaller step works. From safest to least safe:

  1. Allow only your own IP. Add your IP address to the WAF allow list. The rest of the world stays protected.
  2. Turn off one rule. Find the rule ID in the WAF log and disable only that rule.
  3. Turn off the WAF for one domain. Other sites on the server stay protected.
  4. Use detection-only mode. The WAF still logs attacks but does not block them.
  5. Turn the WAF off completely. Use this last.

Steps in cPanel

  1. Log in to cPanel.
  2. Under Security, open ModSecurity, if your plan has it.
  3. Find your domain in the list.
  4. Switch the toggle to Off.
  5. Do your task, for example a plugin update.
  6. Switch the toggle back to On.

Steps in Plesk

  1. Log in to Plesk.
  2. Open Tools & Settings, then Web Application Firewall (ModSecurity).
  3. Change Web application firewall mode to Off or Detection only.
  4. Click OK. Do your task. Then set the mode back to On.

Plesk may also let you change the mode for a single domain in the domain's Web Application Firewall page.

If you do not see these menus, your plan may not include them. Ask Hostvento support.

Stay safe while it is off

  • Set a reminder to turn it on again. Write down the time.
  • Do the task fast. Do not leave admin pages open.
  • Read the log afterward for odd traffic.
  • Add a permanent exception for the rule that caused the problem, so you never need to turn the WAF off again.

Need help? Open a support ticket.

Quick recap

  • Pause a WAF only if you must.
  • Try an IP allow or one-rule exception first.
  • Turn it off for one domain, not the whole server.
  • Turn it back on right after.
  • Back up before you start.