Skip to content

Configure WAF CAPTCHA protection

cPFence v4+ hosted WAF CAPTCHA protects configured paths separately from WordPress math CAPTCHA.

WAF Settings with the cPFence WAF master, global Layer7, Bot and CAPTCHA switches, Reset and Save.

Global WAF controls on the selected server. Shown switches are saved settings, not defaults or a protection test. Select the image for full size; use browser Back to return.
  1. In WAF Management, choose one server and open Settings.
  2. Set CAPTCHA WAF globally, keep cPFence WAF enabled, and Save.
  3. For one domain, use Manage domain → Domain settings → CAPTCHA protection, then Save.
  4. Review the intended login path and legitimate visitor behavior.

As root on the target, use cpfence --enable-captcha-waf-global or cpfence --disable-captcha-waf-global; domain commands are cpfence --enable-captcha-waf-domain example.com and cpfence --disable-captcha-waf-domain example.com.

Manage domain drawer showing WAF, Layer7, Bot and CAPTCHA protection switches.

CAPTCHA has its own domain switch; identities blurred. Select the image for full size; use browser Back to return.

Customize protected URL paths. If cPFence Security Check repeats or does not return to the application, preserve URL, time and engine version for support. Do not assume universal engine/body coverage; see WAF limits.