Skip to content

Troubleshoot a WAF that is not working

Use these checks when cPFence v4+ WAF behavior is unexpected.

WAF Settings with the cPFence WAF master, global Layer7, Bot and CAPTCHA switches, Reset and Save.

Global WAF controls on the selected server. Shown switches are saved settings, not defaults or a protection test. Select the image for full size; use browser Back to return.
  1. Check the affected request and note its URL/time. A single result does not prove universal coverage.
  2. In WAF Management, confirm the correct server, WAF master, global switches, domain settings and disabled-rule exceptions.
  3. Review current WAF events and the relevant web-server error log as root:
Server Read recent errors
LiteSpeed / OpenLiteSpeed tail -n 50 /usr/local/lsws/logs/error.log
Apache tail -n 50 /var/log/apache2/error.log
Nginx tail -n 50 /var/log/nginx/error.log
  1. Resolve the reported configuration or service error. If protection needs reapplying, deliberately use the supported WAF enable control on that server and read its validation/restart result.
  2. Check the request again; if it remains unexpected, contact support with the event and exact engine version.

See managed custom-rule issues and engine qualifications.