Flash Sale:75% Off Hosting + Free DomainEnds in13h47m14sView Plans
Hostvento logoHostvento

How to Protect a Joomla Website With a WAF

This guide shows how to use a web application firewall and a few Joomla settings to keep your Joomla site safer.

Firewall2 min read10 steps

What is Joomla and a WAF?

Joomla is a popular free program for building websites. Because so many sites use it, attackers often look for old or weak Joomla sites.

A WAF is a Web Application Firewall. A firewall is a guard that checks traffic. A WAF reads every visit to your site and blocks the ones that look like attacks. It does this before they reach Joomla.

Before you start

Make a full backup of your Joomla files and database. A database is a digital filing cabinet where Joomla keeps your articles and users.

Steps

  1. Turn on the WAF. In cPanel, open Security, then ModSecurity. In Plesk, open Tools & Settings, then Web Application Firewall. Switch your domain to On.
  2. Make sure the server uses a rule set such as OWASP. Ask Hostvento support if you are not sure.
  3. Open your Joomla site and click around. Log in to the Administrator area. Save an article. Check that nothing breaks.
  4. If the WAF blocks a good action, read the WAF log. Note the rule ID. Ask support to add an exception for that rule on that page.

Add Joomla-specific protection

  1. Update Joomla. In the admin area, open System, then Update. Install new versions of Joomla, extensions and templates. An extension is an add-on, like a plugin.
  2. Remove extensions you do not use. Old add-ons are a common way in.
  3. Turn on two-factor login. Go to Users, then Manage, open your user, and set up multi-factor authentication. It asks for a code from your phone as well as the password.
  4. Use a strong password for each admin account.
  5. Rename or limit the admin user named admin.
  6. Turn on Force HTTPS in System, Global Configuration, Server. HTTPS encrypts traffic between visitors and your site. You need an SSL certificate first.

Limit access to the admin area

If only you log in to /administrator, you can allow only your own IP address in .htaccess. Add a rule in the administrator folder:

Require ip 203.0.113.5

This allows only that address. Replace it with your own IP address. If your IP changes often, do not use this rule.

Warning: A wrong rule can lock you out of the admin area. Back up the .htaccess file first.

Need help? Open a support ticket.

Quick recap

  • A WAF blocks attacks before Joomla sees them.
  • Turn ModSecurity on and test your site.
  • Keep Joomla and all extensions updated.
  • Use strong passwords and two-factor login.
  • Back up before every change.