Modsecurity Vendor Rule
Hello,
I am not to much experience at mod_security.
I have installed Commodo ModSecurity Vendor Rule Set. Should i disable or Enable build in cPanel rule set?
-
Hello :), You can enable/disabled it through WHM. Please check following docs. ModSecurity Vendors - Documentation - cPanel Documentation 0 -
I'm not an expert, but in my experience, it is best to have only one vendor rule set enabled, so you should disable the OWASP rule set if you're going to use the Comodo CWAF vendor rule set. The other thing you should do is go through all the Comodo rules (Security -> ModSecurity Tools -> Rules List) starting from the last page and working forward, and disable all of the rules for software you do not and never will have installed on the server for better performance and fewer false positives. 0 -
I'm not an expert, but in my experience, it is best to have only one vendor rule set enabled, so you should disable the OWASP rule set if you're going to use the Comodo CWAF vendor rule set. The other thing you should do is go through all the Comodo rules (Security -> ModSecurity Tools -> Rules List) starting from the last page and working forward, and disable all of the rules for software you do not and never will have installed on the server for better performance and fewer false positives.
hi, yes i read their notes Warnings: [LIST]- cPanel ModSecurity Vendors are not compatible with CWAF plugin. So, you can't use both in parallel for management your protection rules.
- Don't activate both Comodo Rule Sets for Apache and LiteSpeed simultaneously to avoid conflicts. Release Notes: [LIST]
- In the current version you can't report problems with Comodo rules through cPanel ModSecurity Tools.
- We don't recommend to enable two ModSecurity Vendors simultaneously to avoid possibly logical conflicts and performance issues.
seems it must one to enable0 -
seems it must one to enable
Hello, Yes, this is correct. It's documented on their plugin page at: Deploying Comodo ModSecurity Rule Set in cPanel, Comodo Web Application Firewall v2.4, Firewall Software Thanks!0
Please sign in to leave a comment.
Comments
5 comments