What is a WAF?
A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each visit to your site and blocks those that look like attacks.
Plesk is a control panel. A control panel is a website where you manage your hosting or server. Plesk uses ModSecurity as its WAF. It checks requests against a set of rules.
The server owner switches ModSecurity on for the whole server. A VPS or dedicated server customer has root access and can do this. On other plans, ask Hostvento support if it is available.
Steps for the whole server
- Log in to Plesk as the administrator.
- Click Tools & Settings on the left.
- Under Security, click Web Application Firewall (ModSecurity).
- If you see an install message, click it to add the ModSecurity component first.
- Next to Web application firewall mode, choose On. The other choices are Off and Detection only.
- Pick a Rule set. The free OWASP rule set is a good start. Some servers also offer rule sets from other companies.
- Choose how rules update. Pick Automatically for fresh protection, and choose how often.
- Click OK to save.
Detection only mode writes attacks to the log but does not block them. Use it for a few days on a busy site to find mistakes before you switch to On.
Steps for one domain
- Click Websites & Domains.
- Find your domain and open Web Application Firewall.
- Choose the mode for this site: On, Off, Detection only, or follow the server setting.
- Click OK.
Menu names may differ slightly between Plesk versions. Look for the Web Application Firewall page if a name is not the same.
Check the logs
- Go back to the Web Application Firewall page.
- Open the Logs tab.
- Look for lines that show blocked requests. Note the rule ID.
- If a good action is blocked, add that rule ID to the list of rules to turn off.
Need help? Open a support ticket.
Quick recap
- Plesk uses ModSecurity as its WAF.
- Go to Tools & Settings, then Web Application Firewall (ModSecurity).
- Set the mode to On and choose a rule set.
- Use Detection only to test first.
- Read the logs to spot false positives.