Modsecurity Comodo

DrWizzle

Verified User
Joined
Aug 8, 2021
Messages
267
Location
So'ton
Time for me to post my own question here!

On my test server, I'm testing ModSecurity, if I could get the correct filters loaded! OWASP rules seem to load OK, but for a WP and WHMCS installation they are a bit harsh and I prefer the COMODO rules. They do a similar job but are sympathetic to different server setup scenarios.

My reason for posting here is I've just spun up a test VM with DA 1.688 and tried installing ModSecurity. That's gone fine, and i've had to install OWASP rules instead of COMODO as I get this in Custombuild when I select the COMODO ruleset.


1762028437061.png


Not sure if this is a temp outage by COMODO but the url partly resolves which makes me wonder if this is something more?

1762028553815.png



I have to add, DA are great at adding software to their 'https://files.directadmin.com/[services and more]' for users. Backups of scripts we can download, use or modify & use would be amazing!

As they say.. "The little things in life"
 
Last edited:
Yes, the waf.comodo.com has been down since 2025-10-30. Outages like this happen from time to time. The outage usually does not last longer than a week.

We cache all the rules on our mirror server (files.directadmin.com). However, in addition to the ModSecurity rules, Comodo also tries to install the CWAF client, which needs to be downloaded directly from the Comodo website (we cannot cache it because it does not have versions). So when Comodo has an outage, the CWAF installation fails like it is now.

I hope they will soon fix the waf.comodo.com vhost and everything will continue to work as expected. Otherwise we will most likely rip out the CWAF client and keep installing only the ModSecurity rules (without CWAF client and the plugin that comes with it).
 
Since that's site push behind the CDN, so the issued might come from NuCDN down only IP ".98".
1762094213947.png
 
Thanks guys, much appreciated. I'll try again in the week and see what I get and report back if it fails again.
 
Back
Top