ModSecurity in Web Hosting
We offer ModSecurity with all web hosting plans, so your Internet apps will be protected against harmful attacks. The firewall is switched on by default for all domains and subdomains, but in case you would like, you will be able to stop it via the respective area of your Hepsia Control Panel. You can also switch on a detection mode, so ModSecurity shall keep a log as intended, but shall not take any action. The logs which you will find inside Hepsia are incredibly detailed and feature information about the nature of any attack, when it transpired and from what IP address, the firewall rule that was triggered, and so on. We employ a set of commercial rules which are regularly updated, but sometimes our admins include custom rules as well so as to better protect the sites hosted on our machines.
ModSecurity in Semi-dedicated Servers
All semi-dedicated server packages which we offer include ModSecurity and since the firewall is turned on by default, any site which you set up under a domain or a subdomain will be protected right from the start. A separate section inside the Hepsia Control Panel which comes with the semi-dedicated accounts is dedicated to ModSecurity and it will enable you to stop and start the firewall for any website or enable a detection mode. With the last option, ModSecurity shall not take any action, but it will still identify possible attacks and shall keep all information in a log as if it were 100% active. The logs can be found inside the very same section of the CP and they include specifics about the IP where an attack came from, what its nature was, what rule ModSecurity applies to identify and stop it, and so forth. The security rules which we use on our web servers are a mix of commercial ones from a security firm and custom ones developed by our system admins. Consequently, we offer higher security for your web programs as we can shield them from attacks before security firms release updates for new threats.
ModSecurity in VPS Servers
ModSecurity is pre-installed on all VPS servers which are offered with the Hepsia hosting Control Panel, so your web programs shall be protected from the second your server is in a position. The firewall is activated by default for any domain or subdomain on the VPS, but if needed, you could deactivate it with a click of your mouse from the corresponding section of Hepsia. You could also set it to function in detection mode, so it will maintain a detailed log of any possible attacks without taking any action to prevent them. The logs are available inside the exact same section and offer information about the nature of the attack, what IP it originated from and what ModSecurity rule was initiated to stop it. For optimum security, we use not just commercial rules from a firm working in the field of web security, but also custom ones which our administrators include manually so as to respond to new threats which are still not tackled in the commercial rules.
ModSecurity in Dedicated Servers
ModSecurity is provided by default with all dedicated servers which are set up with the Hepsia Control Panel and is set to “Active” automatically for any domain you host or subdomain you create on the web server. In case that a web app doesn't function properly, you could either turn off the firewall or set it to function in passive mode. The latter means that ModSecurity shall maintain a log of any possible attack that may occur, but will not take any action to prevent it. The logs created in active or passive mode will offer you additional details about the exact file that was attacked, the form of the attack and the IP address it came from, and so forth. This information shall enable you to choose what actions you can take to improve the safety of your Internet sites, including blocking IPs or performing script and plugin updates. The ModSecurity rules we employ are updated regularly with a commercial pack from a third-party security firm we work with, but sometimes our admins include their own rules too when they discover a new potential threat.
