Check the main control panel WAF exception
cPFence v4+ automatically creates a WAF exception for the Enhance main control panel hostname. This lets the panel operate without its requests being inspected by the WAF.
-
As root on the affected licensed server, check the managed exception:
Terminal window grep 'id:1000' /var/lib/cpfcli/waf/panel-exception.conf -
Confirm that the
REQUEST_HEADERS:Hostrule names your main control panel hostname and containsctl:ruleEngine=Off. -
If the rule is missing, reapply WAF protection on that server with
cpfence --enable-cpf-waf. Read the validation/restart result and check the rule and panel access again. If it remains missing or names the wrong hostname, contact support with the error.
The hostname exception does not whitelist server IPs in the firewall. Follow cluster IP whitelisting for the main control panel server, secondary servers and backup servers.
