What is a WAF?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each visit to your website and blocks those that look like attacks, such as hackers trying to break into a login form.
In cPanel, the WAF is usually ModSecurity. cPanel is the control panel for your hosting account. A control panel is a website where you manage your hosting.
The server owner must install ModSecurity and its rules first. On shared hosting, the host does this. If you cannot see the ModSecurity icon, ask Hostvento support if it is available on your plan.
Steps
- Log in to cPanel. Your welcome email from Hostvento has the details.
- Scroll to the Security section.
- Click ModSecurity.
- You see a list of your domains. Each has a switch.
- Turn the switch On for each domain you want to protect.
- Wait a moment. The change is saved on its own.
Some servers also have a button to turn all domains on at once. Look for Enable All.
Check that it works
- Open your website and click around. Make sure pages, forms and the login all work.
- If something fails, the WAF may be blocking a good action. This is a false positive. Try switching the domain Off for a short test, then On again.
- If switching it off fixes the problem, ask Hostvento support to check which rule is the cause. Open a support ticket.
If you have your own server
With a VPS or dedicated server, you have root access and use WHM, the server owner's panel.
- Log in to WHM.
- Search for
ModSecurityand open ModSecurity Configuration. - Set Rules Engine to On.
- Open ModSecurity Vendors and add a rule set, such as OWASP.
- Switch the vendor on.
If ModSecurity is missing, install it through EasyApache 4.
Quick recap
- A WAF blocks attacks before they reach your site.
- In cPanel, open Security, then ModSecurity.
- Switch each domain to On.
- Test your site afterwards.
- Ask support if the icon is missing.