Skip to content

Understand managed WAF rules and custom-rule issues

cPFence v4+ WAF whitelist rules is a Managed entry in Edit Configuration Files. Use WAF rule and domain controls for the supported exception tasks.

Choose Open WAF Management from this read-only managed entry to use its owning controls.

WAF whitelist rules marked Managed, with Managed in WAF Management Database and Open WAF Management.

This managed entry routes to WAF Management instead of an editable file. No rule content is exposed or changed. Select the image for full size; use browser Back to return.

The main control panel hostname exception is also managed automatically; check it separately if panel requests are affected.

  1. Identify the rule ID from the failed request and confirm the correct server/domain.
  2. Inspect disabled-rule exceptions in Manage domain.
  3. Add or remove only the intended exception through the supported control.
  4. Review the resulting request and web-server errors.

Domain exceptions are narrower than disabling a rule globally. If the supported controls do not express your requirement, contact support with the desired scope and matching WAF event before adding manual directives.