How to Set Up a Web Application Firewall

Add a web application firewall to filter malicious traffic before it reaches your site and block common attack patterns.

· Updated · 2,073 views

A web application firewall (WAF) sits between visitors and your site, filtering out malicious requests such as SQL injection, cross-site scripting, and bad bots. It is one of the most effective ways to reduce attacks reaching your application.

Choose a Firewall Type

| Type | How It Works | | --- | --- | | Server WAF | Runs on the hosting server, like ModSecurity | | Cloud WAF | Filters traffic before it reaches your host | | Plugin WAF | Runs inside your application, such as WordPress |

Each layer adds protection, and they can work together.

Use Server-Level ModSecurity

Many cPanel servers include ModSecurity:

  1. Log in to cPanel.
  2. Look for ModSecurity under the Security section.
  3. Confirm it is enabled for your domain.
  4. If a rule blocks legitimate traffic, note the rule ID for support.

If you do not see the tool, ModSecurity may be managed server-wide by your host.

Add a Cloud Firewall

A cloud WAF, such as Cloudflare, filters traffic before it reaches your server:

  1. Sign up and add your domain.
  2. Update your domain's nameservers as instructed.
  3. Enable the firewall and security rules in the dashboard.
  4. Set the security level to suit your traffic.

Add a Plugin Firewall

For WordPress, a security plugin provides an application-level firewall:

  • Block known malicious IPs and bots.
  • Limit login attempts.
  • Patch common vulnerabilities virtually.

Combining a server or cloud WAF with a plugin firewall gives layered defense. If a firewall rule blocks a real visitor or breaks a feature, contact support via the /contact page with the request details so the rule can be tuned.

Was this article helpful?

Your feedback helps us improve our documentation.

Still Need Help?

Our support team is available 24/7 to assist you.