Skip to content

Check the main control panel WAF exception

cPFence v4+ automatically creates a WAF exception for the Enhance main control panel hostname. This lets the panel operate without its requests being inspected by the WAF.

  1. As root on the affected licensed server, check the managed exception:

    Terminal window
    grep 'id:1000' /var/lib/cpfcli/waf/panel-exception.conf
  2. Confirm that the REQUEST_HEADERS:Host rule names your main control panel hostname and contains ctl:ruleEngine=Off.

  3. If the rule is missing, reapply WAF protection on that server with cpfence --enable-cpf-waf. Read the validation/restart result and check the rule and panel access again. If it remains missing or names the wrong hostname, contact support with the error.

The hostname exception does not whitelist server IPs in the firewall. Follow cluster IP whitelisting for the main control panel server, secondary servers and backup servers.