LSF WAF false positive

LSF does not replace WHM → ModSecurity Vendors (OWASP CRS / Atomicorp). It loads a supplementary ruleset into modsec2.user.conf with apachectl configtest and automatic rollback on failure.

WAF tab

Unload from the WAF tab or lsf --waf-unload. Disable one rule globally or per domain: Rule ID + Disable, or lsf --waf-disable ID [domain]. If the IP was also firewall-banned, Remove it on Overview. WAF bans use a stricter separate threshold (default 2× LF_TRIGGER).

  • lsf, waf
  • 0 Users Found This Useful
Was this answer helpful?

Related Articles

GeoIP country blocking in LSF

CC_DENY="CN,RU,KP" CC_ALLOW="GR,CY,DE" CC_DENY drops all inbound from those countries. CC_ALLOW...

LFD and PSAD — brute force and port scans

LFD watches SSH, FTP, mail, Exim, cPanel and ModSecurity failures. Default: 5 hits in 300 seconds...

Which ports does Lion Server Firewall open

Default TCP_IN: 20, 21, 22, 25, 26, 53, 80, 110, 143, 443, 465, 587, 993, 995, 2082, 2083, 2086,...

Locked out of the server by LSF

TESTING mode: wait up to 5 minutes for the auto-flush. Lionhost KVM / VNC / IPMI as root: lsf...

[STAFF] LSF ticket reply

STAFF ONLY — do not publish. Ask for the customer public IP. lsf --search IP or Simulator. lsf...