What is a WAF?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF protects your website by blocking requests that look like attacks.
It can make mistakes. It may block a page builder, a payment callback or a plugin update. This is called a false positive: a good action treated as bad. Then you may want to pause the WAF to see if it is the cause.
Safer choices first
Do not switch everything off if a smaller step works. From safest to least safe:
- Allow only your own IP. Add your IP address to the WAF allow list. The rest of the world stays protected.
- Turn off one rule. Find the rule ID in the WAF log and disable only that rule.
- Turn off the WAF for one domain. Other sites on the server stay protected.
- Use detection-only mode. The WAF still logs attacks but does not block them.
- Turn the WAF off completely. Use this last.
Steps in cPanel
- Log in to cPanel.
- Under Security, open ModSecurity, if your plan has it.
- Find your domain in the list.
- Switch the toggle to Off.
- Do your task, for example a plugin update.
- Switch the toggle back to On.
Steps in Plesk
- Log in to Plesk.
- Open Tools & Settings, then Web Application Firewall (ModSecurity).
- Change Web application firewall mode to Off or Detection only.
- Click OK. Do your task. Then set the mode back to On.
Plesk may also let you change the mode for a single domain in the domain's Web Application Firewall page.
If you do not see these menus, your plan may not include them. Ask Hostvento support.
Stay safe while it is off
- Set a reminder to turn it on again. Write down the time.
- Do the task fast. Do not leave admin pages open.
- Read the log afterward for odd traffic.
- Add a permanent exception for the rule that caused the problem, so you never need to turn the WAF off again.
Need help? Open a support ticket.
Quick recap
- Pause a WAF only if you must.
- Try an IP allow or one-rule exception first.
- Turn it off for one domain, not the whole server.
- Turn it back on right after.
- Back up before you start.