{"id":7414,"date":"2026-08-20T16:55:27","date_gmt":"2026-08-20T14:55:27","guid":{"rendered":"https:\/\/www.webhostingsrbija.rs\/?p=7414"},"modified":"2026-08-20T16:55:27","modified_gmt":"2026-08-20T14:55:27","slug":"modsecurity-waf","status":"publish","type":"post","link":"https:\/\/www.webhostingsrbija.rs\/en\/modsecurity-waf\/","title":{"rendered":"ModSecurity WAF (firewall) in WHSPanel"},"content":{"rendered":"<p>Web Application Firewall (WAF) inspects every HTTP request to your domains and blocks attacks like SQL injection, XSS (cross-site scripting), file inclusion and code execution before they reach your application. It stands between the internet and the site and automatically catches common attack patterns. Engine is OWASP Coraza.<\/p>\n\n<h2>1. Domain protection<\/h2>\n<p>Open in the menu <strong>Security<\/strong> well <strong>ModSecurity (WAF)<\/strong>. On the card <strong>Domain protection<\/strong> you enable WAF per domain and choose the mode and rule level. The tab shows how many domains are protected.<\/p>\n\n\n<figure data-wp-context=\"{&quot;imageId&quot;:&quot;6ac327badaaa3&quot;}\" data-wp-interactive=\"core\/image\" data-wp-key=\"6ac327badaaa3\" class=\"wp-block-image size-large wp-lightbox-container\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"789\" data-wp-class--hide=\"state.isContentHidden\" data-wp-class--show=\"state.isContentVisible\" data-wp-init=\"callbacks.setButtonStyles\" data-wp-on--click=\"actions.showLightbox\" data-wp-on--load=\"callbacks.setButtonStyles\" data-wp-on--pointerdown=\"actions.preloadImage\" data-wp-on--pointerenter=\"actions.preloadImageWithDelay\" data-wp-on--pointerleave=\"actions.cancelPreload\" data-wp-on-window--resize=\"callbacks.setButtonStyles\" src=\"https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-1024x789.avif\" alt=\"ModSecurity WAF u WHSPanelu\" class=\"wp-image-7497\" title=\"\" srcset=\"https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-1024x789.avif 1024w, https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-300x231.avif 300w, https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-768x592.avif 768w, https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-1536x1184.avif 1536w, https:\/\/www.webhostingsrbija.rs\/wp-content\/uploads\/2026\/08\/sec-waf-a-2048x1579.avif 2048w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><button\n\t\t\tclass=\"lightbox-trigger\"\n\t\t\ttype=\"button\"\n\t\t\taria-haspopup=\"dialog\"\n\t\t\tdata-wp-bind--aria-label=\"state.thisImage.triggerButtonAriaLabel\"\n\t\t\tdata-wp-init=\"callbacks.initTriggerButton\"\n\t\t\tdata-wp-on--click=\"actions.showLightbox\"\n\t\t\tdata-wp-style--right=\"state.thisImage.buttonRight\"\n\t\t\tdata-wp-style--top=\"state.thisImage.buttonTop\"\n\t\t>\n\t\t\t<svg xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"12\" height=\"12\" fill=\"none\" viewbox=\"0 0 12 12\">\n\t\t\t\t<path fill=\"#fff\" d=\"M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z\" \/>\n\t\t\t<\/svg>\n\t\t<\/button><figcaption class=\"wp-block-image__caption\">Web Application Firewall by domain, with operating mode and paranoia level.<\/figcaption><\/figure>\n\n\n<h2>2. Operating mode<\/h2>\n<table>\n<thead><tr><th>Mode<\/th><th>What does it do?<\/th><\/tr><\/thead>\n<tbody>\n<tr><td><strong>Detect<\/strong><\/td><td>It only records attacks, nothing is blocked. Use to steltel before you turn on blocking.<\/td><\/tr>\n<tr><td><strong>Block<\/strong><\/td><td>Actively rejects attacks with error 403. Recommended when the rule is compensated.<\/td><\/tr>\n<\/tbody>\n<\/table>\n\n<h2>3. Level of paranoia<\/h2>\n<p>The level determines how strict the rules are:<\/p>\n<ul>\n<li><strong>PL1 Basic:<\/strong> default, catches common attacks with almost no fake blocks. Recommended for most sites.<\/li>\n<li><strong>PL2 Reinforced:<\/strong> stricter checking, slightly higher chance of blocking a legitimate request.<\/li>\n<li><strong>PL3 Aggressive:<\/strong> strict rules for sensitive sites, with some fake blocking.<\/li>\n<li><strong>PL4 Maximum:<\/strong> strictest, many legitimate requests may be blocked. Only for well-tested sites.<\/li>\n<\/ul>\n<p>On the card <strong>Exceptions<\/strong> you can whitelist certain addresses or rules if the WAF blocks something legitimate.<\/p>\n\n<blockquote><p><strong>Note:<\/strong> if the WAF makes fake blocks of legitimate site functions, it is better to add <strong>exception<\/strong> or lower the paranoia level than shut down the entire WAF. Even when WAF is turned off for a domain, the site is still protected by other layers (fail2ban, rate limiting, anti-DDoS protection, malware scanner, account isolation, and SSL), but application-level attacks are no longer filtered.<\/p><\/blockquote>","protected":false},"excerpt":{"rendered":"<p>How to turn on WAF per domain in WHSPanel and choose mode (Detect or Block) and paranoia level.<\/p>","protected":false},"author":1,"featured_media":7311,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"site-sidebar-layout":"default","site-content-layout":"","ast-site-content-layout":"default","site-content-style":"default","site-sidebar-style":"default","ast-global-header-display":"","ast-banner-title-visibility":"","ast-main-header-display":"","ast-hfb-above-header-display":"","ast-hfb-below-header-display":"","ast-hfb-mobile-header-display":"","site-post-title":"","ast-breadcrumbs-content":"","ast-featured-img":"","footer-sml-layout":"","ast-disable-related-posts":"","theme-transparent-header-meta":"","adv-header-id-meta":"","stick-header-meta":"","header-above-stick-meta":"","header-main-stick-meta":"","header-below-stick-meta":"","astra-migrate-meta-layouts":"default","ast-page-background-enabled":"default","ast-page-background-meta":{"desktop":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"ast-content-background-meta":{"desktop":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"tablet":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""},"mobile":{"background-color":"var(--ast-global-color-5)","background-image":"","background-repeat":"repeat","background-position":"center center","background-size":"auto","background-attachment":"scroll","background-type":"","background-media":"","overlay-type":"","overlay-color":"","overlay-opacity":"","overlay-gradient":""}},"footnotes":""},"categories":[210,203],"tags":[],"class_list":["post-7414","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bezbednost-panel","category-whs-panel"],"_links":{"self":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts\/7414","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/comments?post=7414"}],"version-history":[{"count":1,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts\/7414\/revisions"}],"predecessor-version":[{"id":7513,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/posts\/7414\/revisions\/7513"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/media\/7311"}],"wp:attachment":[{"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/media?parent=7414"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/categories?post=7414"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.webhostingsrbija.rs\/en\/wp-json\/wp\/v2\/tags?post=7414"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}