Skip to content

WAF and CAPTCHA

In cPFence v4+, open WAF Management to review blocked requests and change domain protection. Administrators can use all controls; support users need target-server access and separate history, domain, rule, global-protection, or tracking permissions.

  1. Choose the server or cluster subset in Server scope.
  2. Open WAF Summary. Set Summary period for totals.
  3. Filter Recent blocked requests by search, domain, date, or server, then Apply filters.
  4. Open request details and check the server, domain, path, source IP, rule ID, and event time.

Old blocks can remain after policy changes. Use Refresh and current policy details before changing a rule.

Blocked request details showing rule ID, HTTP 403 enforcement, Rule active for this domain and Disable rule for this domain.

An existing ordinary-rule event with its domain action available; identifying details are blurred. No exception is applied in this example. Select the image for full size; use browser Back to return.

After verifying a false positive, follow disable or re-enable a WAF rule. That task covers a narrow domain exception, reversal and the broader global-ID commands.

Manage domain → Domain settings contains the domain’s WAF, Layer7, Bot and CAPTCHA switches. Use the focused rule/domain task, domain Layer7 task, domain bot task or CAPTCHA task for steps and CLI equivalents.

Manage domain drawer with WAF, Layer7, Bot, and CAPTCHA switches and the Disabled rules list.

Domain protection controls; identities blurred. Select the image for full size; use browser Back to return.

For server-wide changes, use enable/disable WAF, global Layer7, global bot protection or CAPTCHA protection. Domain switches do not activate protection while the master is off.

WAF Settings with the cPFence WAF master, global Layer7, Bot and CAPTCHA switches, Reset and Save.

Global WAF controls on the selected server. Shown switches are saved settings, not defaults or a protection test. Select the image for full size; use browser Back to return.

Reset → Confirm reset restores these global settings to packaged defaults; check the affected server before confirming.

The matching Advanced Tools actions use sidebar bulk targets. Check those targets before confirming and read each server’s output; some can succeed while others fail. Disabling the master or a rule removes that protection from the affected scope.

Use identify a problematic WAF rule for domain or server-wide live tracking.

For Report False Positive, fill Subject and Details, attach the full WAF log entry with rule ID in an accepted type, and Send. Submission does not create an exception or prove recipient review. Omit credentials and unrelated private data.

Report WAF False Positive form with Subject, Details, Attachment and Send.

Include the full WAF log entry and rule ID for review. The blank form does not show a submitted report or delivery result. Select the image for full size; use browser Back to return.

Hosted WAF CAPTCHA is separate from WordPress math CAPTCHA. Initial requests and cookie/referrer/query exemptions can avoid a challenge. If cPFence Security Check repeats or does not return to the application, preserve the affected URL, time, and web-server version when asking for support.

See configure CAPTCHA for activation and login-cache guidance, or check WAF protection and WAF troubleshooting for an unexpected request. XML-RPC blocking belongs to WordPress bulk security.

Coverage depends on the web-server engine and request type; do not assume static files or JSON receive the same inspection as dynamic form requests. Current engine limits include:

  • OpenLiteSpeed 1.9.2 / libmodsecurity 3.0.15: tested JSON XSS/SQL injection passed while form/multipart controls blocked.
  • LiteSpeed Enterprise 6.3.5 build 5: JSON inspection differs between HTTP/1.1 and HTTP/2; form blocking does not prove correct JSON parsing.
  • LiteSpeed Enterprise 6.4 RC2 build 2: target exclusions can cause HTTP 500 for legitimate requests. Do not assume a newer version label proves compatibility.

Preserve the log and exact engine version when asking for support. Do not disable setup guards or lower global thresholds to hide an engine problem.