Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Turn On the WAF (ModSecurity) in cPanel

This guide shows how to switch on web application firewall protection for your domains in cPanel.

Firewall2 min read14 steps

What is a WAF?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each visit to your website and blocks those that look like attacks, such as hackers trying to break into a login form.

In cPanel, the WAF is usually ModSecurity. cPanel is the control panel for your hosting account. A control panel is a website where you manage your hosting.

The server owner must install ModSecurity and its rules first. On shared hosting, the host does this. If you cannot see the ModSecurity icon, ask Hostvento support if it is available on your plan.

Steps

  1. Log in to cPanel. Your welcome email from Hostvento has the details.
  2. Scroll to the Security section.
  3. Click ModSecurity.
  4. You see a list of your domains. Each has a switch.
  5. Turn the switch On for each domain you want to protect.
  6. Wait a moment. The change is saved on its own.

Some servers also have a button to turn all domains on at once. Look for Enable All.

Check that it works

  1. Open your website and click around. Make sure pages, forms and the login all work.
  2. If something fails, the WAF may be blocking a good action. This is a false positive. Try switching the domain Off for a short test, then On again.
  3. If switching it off fixes the problem, ask Hostvento support to check which rule is the cause. Open a support ticket.
Tip: Back up your site before you test. If your plan has a backup tool in cPanel, look under Files for Backup.

If you have your own server

With a VPS or dedicated server, you have root access and use WHM, the server owner's panel.

  1. Log in to WHM.
  2. Search for ModSecurity and open ModSecurity Configuration.
  3. Set Rules Engine to On.
  4. Open ModSecurity Vendors and add a rule set, such as OWASP.
  5. Switch the vendor on.

If ModSecurity is missing, install it through EasyApache 4.

Tip: A WAF does not replace updates. Keep your website software, themes and plugins updated, and use strong passwords.

Quick recap

  • A WAF blocks attacks before they reach your site.
  • In cPanel, open Security, then ModSecurity.
  • Switch each domain to On.
  • Test your site afterwards.
  • Ask support if the icon is missing.