Understand managed WAF rules and custom-rule issues
cPFence v4+ WAF whitelist rules is a Managed entry in Edit Configuration Files. Use WAF rule and domain controls for the supported exception tasks.
Choose Open WAF Management from this read-only managed entry to use its owning controls.
The main control panel hostname exception is also managed automatically; check it separately if panel requests are affected.
- Identify the rule ID from the failed request and confirm the correct server/domain.
- Inspect disabled-rule exceptions in Manage domain.
- Add or remove only the intended exception through the supported control.
- Review the resulting request and web-server errors.
Domain exceptions are narrower than disabling a rule globally. If the supported controls do not express your requirement, contact support with the desired scope and matching WAF event before adding manual directives.

