Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
ShieldCache 4 min read

Firewall (WAF): mode, check level, categories, exceptions and WAF log

The Web Application Firewall (WAF) checks every request against the OWASP Core Rule Set and detects attacks such as SQL injection, cross-site scripting or command execution. You will find it in the Firewall tab with the sub-tabs Settings, Exceptions and Log.

Mode

  • Detect only: Attacks are logged but not blocked. Every new site starts like this - the overview shows the date until which this test phase runs.
  • Block: Detected attacks are rejected with an error page including a reference (SC-403-WAF).
  • Off: no checks. Only use this briefly for troubleshooting - without the firewall, your website is not protected against attacks.

Once the test phase is over, the overview shows “Recommendation: activate blocking”. Then check the WAF log for false positives, create exceptions and switch to Block.

Check level and application profiles

  • Level 1: basic protection with very few false positives - right for most websites.
  • Level 2: additional rules, occasional false positives - for websites with increased protection requirements.
  • Level 3: very strict, more frequent false positives - only useful with exceptions for your application.

Application profiles exclude known false positives of widely used applications: WordPress, WooCommerce, Shopware, Laravel, WoltLab, Hostware and API (JSON). Choose what runs on the site.

Web Application Firewall settings with mode, check level and application profiles
Firewall settings: mode, check level and application profiles.

Attack categories

Under Attack categories you switch entire groups of rules on or off: scanner detection, protocol violations, protocol attacks, multipart attacks, local and remote files (LFI/RFI), command execution, PHP attacks, general attacks, cross-site scripting, SQL injection, session fixation and Java attacks. This is better than switching off individual rules if a category is irrelevant for your application - for example Java on a PHP website. Categories that are switched off are no longer detected, which is why the card shows a warning.

Firewall attack categories with 13 switches
The 13 attack categories with their respective rule ranges.

WAF log

The Log sub-tab lists all requests with rule matches from the last 30 days: time, reference, method, address, client IP, rules and action (“Blocked” or “Detected only” with the anomaly score). Matched content is shortened and sensitive values are masked. Filter by action, rule or search term; new events arrive automatically every 5 minutes, instantly with ↻. A click on the arrow shows all matches of a request with message and matched content.

WAF log with time, reference, address, client IP, rules and action
The WAF log: each row is a request, with the “Exception” button on the right.

Check reference

Every ShieldCache error page shows an error code and a reference. If a visitor contacts you with a reference, click Check reference at the top of the site and enter it. You will see what happened to the request: status, address, duration, user agent and all firewall matches. From there you can create an exception directly or allow the IP.

“Check reference” dialogue with access and the firewall matches
“Check reference” shows the access and the rules that were triggered.

Exceptions per path

If legitimate access triggers rules - for example an editor in the admin area or an interface - create an exception. The selected rules are then switched off for this path only, and all others continue to check.

  1. In the WAF log, click Exception in the row of the false positive. Path and rules are pre-filled.
  2. Check the path and under “Applies to” choose Exactly this path or Starts with. Keep the exception as narrow as possible.
  3. Choose the action: Release switches the rules off and no longer logs anything. Release & log no longer blocks, but still shows matches in the WAF log with the label “released by exception” - ideal for observing an exception first. From a log entry, “Release & log” is suggested.
  4. Click Save and then Apply at the top.
“Add exception” dialogue, pre-filled from a log entry
An exception from a log entry: path and rules are pre-filled.

All exceptions are listed in the Exceptions sub-tab, up to 100 per site. “Release & log” only works with request rules (910000 to 944999). The attack rules 910000 to 944999 and 950000 to 956999 can be switched off; the evaluation rules always remain active.

List of exceptions per path with the action Release & log
Exceptions per path with action, rules and note.

Exception instead of switching off site-wide

In the settings you can also switch off rules for the whole site. This then applies to all paths. An exception for the affected path only is almost always better.

How long does the test phase in “Detect only” mode last?

New sites start in “Detect only” mode, and the overview shows the end date. After that, the mode remains until you change it yourself - the overview then recommends switching.

Are IP addresses stored in the WAF log?

IP addresses are only stored in full in the log for 7 days, after which they are shortened (IPv4 to the /24 network, IPv6 to /48, label “shortened”). After 30 days, the entries are deleted. To search for a shortened IP, use the shortened form.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

Alles bestens

Bei SpeedIT werden wird gut betreut und alles klappt wie gewünscht. Unsere Wünsche werden erfüllt und der Support ist gut erreichbar.
Marcel W.Recommends us · 10/03/2025

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.