ModSecurity in Semi-dedicated Servers
Any web application which you install inside your new semi-dedicated server account will be protected by ModSecurity because the firewall is provided with all our hosting plans and is turned on by default for any domain and subdomain that you include or create through your Hepsia hosting Control Panel. You shall be able to manage ModSecurity through a dedicated area in Hepsia where not simply could you activate or deactivate it entirely, but you may also enable a passive mode, so the firewall shall not block anything, but it will still keep a record of possible attacks. This normally requires only a click and you will be able to view the logs no matter if ModSecurity is in active or passive mode through the same section - what the attack was and where it originated from, how it was dealt with, and so on. The firewall uses 2 groups of rules on our machines - a commercial one which we get from a third-party web security provider and a custom one that our administrators update personally in order to respond to recently discovered risks at the earliest opportunity.
ModSecurity in VPS Servers
ModSecurity is included with all Hepsia-based VPS servers we offer and it shall be activated automatically for any new domain or subdomain that you add on the server. That way, any web application you install shall be protected from the very beginning without doing anything personally on your end. The firewall could be managed via the section of the Control Panel that bears the same name. This is the area whereyou can switch off ModSecurity or activate its passive mode, so it will not take any action against threats, but will still maintain a thorough log. The recorded data is available in the same area as well and you shall be able to see what IPs any attacks originated from to enable you to block them, what the nature of the attempted attacks was and based upon what security rules ModSecurity reacted. The rules that we use on our servers are a blend between commercial ones which we obtain from a security firm and custom ones that are added by our admins to optimize the security of any web apps hosted on our end.
ModSecurity in Dedicated Servers
If you opt to host your sites on a dedicated server with the Hepsia Control Panel, your web apps shall be protected right from the start as ModSecurity is supplied with all Hepsia-based packages. You shall be able to manage the firewall easily and if necessary, you'll be able to turn it off or switch on its passive mode when it'll only maintain a log of what is taking place without taking any action to prevent potential attacks. The logs that you can find inside the very same section of the CP are quite detailed and feature information about the attacker IP, what site and file were attacked and in what ways, what rule the firewall used to stop the intrusion, and so forth. This information shall permit you to take measures and enhance the security of your websites even more. To be on the safe side, we employ not only commercial rules, but also custom-made ones that our admins add every time they identify attacks which have not yet been included inside the commercial pack.
