Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Turn On the Web Application Firewall in Plesk

This guide shows how to switch on ModSecurity, the web application firewall, in the Plesk control panel.

Firewall2 min read16 steps

What is a WAF?

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads each visit to your site and blocks those that look like attacks.

Plesk is a control panel. A control panel is a website where you manage your hosting or server. Plesk uses ModSecurity as its WAF. It checks requests against a set of rules.

The server owner switches ModSecurity on for the whole server. A VPS or dedicated server customer has root access and can do this. On other plans, ask Hostvento support if it is available.

Steps for the whole server

  1. Log in to Plesk as the administrator.
  2. Click Tools & Settings on the left.
  3. Under Security, click Web Application Firewall (ModSecurity).
  4. If you see an install message, click it to add the ModSecurity component first.
  5. Next to Web application firewall mode, choose On. The other choices are Off and Detection only.
  6. Pick a Rule set. The free OWASP rule set is a good start. Some servers also offer rule sets from other companies.
  7. Choose how rules update. Pick Automatically for fresh protection, and choose how often.
  8. Click OK to save.

Detection only mode writes attacks to the log but does not block them. Use it for a few days on a busy site to find mistakes before you switch to On.

Steps for one domain

  1. Click Websites & Domains.
  2. Find your domain and open Web Application Firewall.
  3. Choose the mode for this site: On, Off, Detection only, or follow the server setting.
  4. Click OK.

Menu names may differ slightly between Plesk versions. Look for the Web Application Firewall page if a name is not the same.

Check the logs

  1. Go back to the Web Application Firewall page.
  2. Open the Logs tab.
  3. Look for lines that show blocked requests. Note the rule ID.
  4. If a good action is blocked, add that rule ID to the list of rules to turn off.
Tip: After switching the WAF on, open your site, log in, and send a form. Make sure all still works. Take a backup before big changes.

Need help? Open a support ticket.

Quick recap

  • Plesk uses ModSecurity as its WAF.
  • Go to Tools & Settings, then Web Application Firewall (ModSecurity).
  • Set the mode to On and choose a rule set.
  • Use Detection only to test first.
  • Read the logs to spot false positives.