ModSecurity and web application firewalls: what they do, and what to do when one blocks you

The short answer: a web application firewall (WAF) reads every request reaching your site and refuses the ones shaped like an attack. ModSecurity is the best-known engine, and it is the one running on our servers with a maintained rule set. Most of the time it works unnoticed; now and then it blocks something legitimate, and that case has a fix, though not switching everything off.

What each piece is

Piece What it looks at Where it sits
Network firewall (CSF/LFD) Who connects and how often they fail: it blocks addresses that repeat attempts. On the server. See why your IP gets blocked.
ModSecurity (server WAF) The content of each web request: attempts to inject SQL, read files, ask for .env or .git. On the server, before your site runs.
A WAF in a CDN The same kind of request, but before it reaches the server. It also deals with mass traffic. In a service you choose, such as Cloudflare. See what Cloudflare is.
WordPress security plugin Requests that reach WordPress, already inside the application. On your site.

They are layers that add up, not replacements for one another. What runs on every server is described in what we do about security, and what stays yours.

When it blocks something legitimate

The sign is a 403 error or a refusal page that appears when you do one particular thing: saving a post with embedded code, sending a form with text that looks like an SQL statement, uploading a file, using a plugin that calls the server in an unusual way. The rest of the site opens fine. This is called a “false positive”.

1 Note the essentials: the exact time, the page address, what you were doing, and your IP address (see how to find your public IP).
2 Try simplifying what you sent. If the block appears when you paste a block of code into a text field, try a shorter version or one without the typical code characters. It helps you see which piece sets the rule off.
3 Do not repeat the request many times. Each refusal counts, and the network firewall may block your address: see how to unblock your IP.
4 Open a support ticket with those details. We read the server log, see which rule fired, and tell you whether the refusal was right or whether an adjustment is possible for your case.
Asking to “switch ModSecurity off” is rarely the best answer. Turning off the engine leaves the site open to malicious requests of every kind, to solve a block from a single rule. An adjustment for that rule may be possible; do not count on more than that, and bear in mind that a rule maintained by others may also be the one saving you from a flaw in the plugin you are using.
Need a WAF layer ahead of the server, for a site with real adversaries or a lot of automated traffic? Read the Cloudflare options worth having, and the ones that cause trouble. That one is yours, under your own account with the service.

A 403 error that appears only on one specific action? Send us the time, the address and what you did.

Open a support ticket

SEE ALSO

What we do about security, DDoS included, and what stays yours

Error 403 Forbidden: permissions, .htaccess and blocked IPs

Why your IP gets blocked by the firewall

How to unblock your IP address

RECOMMENDED PRODUCT

Web hosting with cPanel

Domain and SSL included, daily backups and the panel you already know. from $6.60/mo (3-year plan, with coupon)

See plans
  • 0 Users Found This Useful
Was this answer helpful?