WAF and CAPTCHA
In cPFence v4+, open WAF Management to review blocked requests and change domain protection. Administrators can use all controls; support users need target-server access and separate history, domain, rule, global-protection, or tracking permissions.
Find a blocked request
Section titled “Find a blocked request”- Choose the server or cluster subset in Server scope.
- Open WAF Summary. Set Summary period for totals.
- Filter Recent blocked requests by search, domain, date, or server, then Apply filters.
- Open request details and check the server, domain, path, source IP, rule ID, and event time.
Old blocks can remain after policy changes. Use Refresh and current policy details before changing a rule.
Disable one rule for one domain
Section titled “Disable one rule for one domain”After verifying a false positive, follow disable or re-enable a WAF rule. That task covers a narrow domain exception, reversal and the broader global-ID commands.
Change domain or global protection
Section titled “Change domain or global protection”Manage domain → Domain settings contains the domain’s WAF, Layer7, Bot and CAPTCHA switches. Use the focused rule/domain task, domain Layer7 task, domain bot task or CAPTCHA task for steps and CLI equivalents.
For server-wide changes, use enable/disable WAF, global Layer7, global bot protection or CAPTCHA protection. Domain switches do not activate protection while the master is off.
Reset → Confirm reset restores these global settings to packaged defaults; check the affected server before confirming.
The matching Advanced Tools actions use sidebar bulk targets. Check those targets before confirming and read each server’s output; some can succeed while others fail. Disabling the master or a rule removes that protection from the affected scope.
Track and report a false positive
Section titled “Track and report a false positive”Use identify a problematic WAF rule for domain or server-wide live tracking.
For Report False Positive, fill Subject and Details, attach the full WAF log entry with rule ID in an accepted type, and Send. Submission does not create an exception or prove recipient review. Omit credentials and unrelated private data.
CAPTCHA and engine limits
Section titled “CAPTCHA and engine limits”Hosted WAF CAPTCHA is separate from WordPress math CAPTCHA. Initial requests and cookie/referrer/query exemptions can avoid a challenge. If cPFence Security Check repeats or does not return to the application, preserve the affected URL, time, and web-server version when asking for support.
See configure CAPTCHA for activation and login-cache guidance, or check WAF protection and WAF troubleshooting for an unexpected request. XML-RPC blocking belongs to WordPress bulk security.
Coverage depends on the web-server engine and request type; do not assume static files or JSON receive the same inspection as dynamic form requests. Current engine limits include:
- OpenLiteSpeed 1.9.2 / libmodsecurity 3.0.15: tested JSON XSS/SQL injection passed while form/multipart controls blocked.
- LiteSpeed Enterprise 6.3.5 build 5: JSON inspection differs between HTTP/1.1 and HTTP/2; form blocking does not prove correct JSON parsing.
- LiteSpeed Enterprise 6.4 RC2 build 2: target exclusions can cause HTTP 500 for legitimate requests. Do not assume a newer version label proves compatibility.
Preserve the log and exact engine version when asking for support. Do not disable setup guards or lower global thresholds to hide an engine problem.




