Cloud Service >> Knowledgebase >> DirectAdmin >> How to Enable and Disable ModSecurity Rules with DirectAdmin
submit query

Cut Hosting Costs! Submit Query Today!

How to Enable and Disable ModSecurity Rules with DirectAdmin

ModSecurity is a powerful web application firewall that helps protect your website from various attacks by filtering and monitoring HTTP traffic. With DirectAdmin, you can easily manage ModSecurity rules to suit your specific needs. Below is a step-by-step guide on turning ModSecurity rules on and off using DirectAdmin.

Access DirectAdmin

1. Log in to your DirectAdmin control panel.

2 Navigate to the Admin or User Level areas, depending on your permissions.

Access ModSecurity Settings

1. Under the Extra Features section, look for ModSecurity. Click on it to open the ModSecurity management interface.

2. If you don’t see the ModSecurity option, you may need to enable it through the DirectAdmin configuration or ask your cloud hosting provider for assistance.

View Current ModSecurity Rules

1.Once inside the ModSecurity management interface, you’ll see a list of all active ModSecurity rules.

2. Each rule is identified by a unique ID (Rule ID). You can also see descriptions of what each rule does.

Disable Specific ModSecurity Rules

1. Locate the rule you want to disable from the list.

2. Click the Disable button next to the rule.

3. Confirm your action if prompted.

4. Alternatively, add the Rule ID to a custom list of disabled regulations. This is usually done in a configuration file (modsec2.user.conf) within the server, but the interface should allow direct disabling for most users.

 

Enable Specific ModSecurity Rules

1. To enable a rule previously turned off, find it in the disabled rules list.

2. Click the Enable button next to the rule.

3. Confirm your action.

Apply Changes

1. After enabling or disabling rules, apply or save your changes.

2. The ModSecurity service may restart automatically, or you might be prompted to restart it manually.

Testing

1. After changing the ModSecurity rules, it’s a good idea to test your website to ensure that everything functions correctly.

2. Check the ModSecurity logs (accessible through DirectAdmin) to see if any rules are being triggered unnecessarily or if legitimate traffic is blocked.

Important Considerations

Backup Configuration: Before making any changes, consider backing up your current ModSecurity configuration. This ensures you can revert to a previous state if something goes wrong.

Rule Updates: ModSecurity rules are updated regularly to protect against new threats. If you turn off a rule, understand the potential risks.

Customization: You can customize ModSecurity rules to suit your specific application needs better. This might involve editing the rules directly, which requires a good understanding of ModSecurity syntax.

By following these steps, you can efficiently manage ModSecurity rules in DirectAdmin, turning them on and off as needed to optimize the security and performance of your website.

Cut Hosting Costs! Submit Query Today!

Grow With Us

Let’s talk about the future, and make it happen!