Skip to content

modsecurity.conf last file #3367

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
Max131412 opened this issue Apr 25, 2025 · 5 comments
Open

modsecurity.conf last file #3367

Max131412 opened this issue Apr 25, 2025 · 5 comments

Comments

@Max131412
Copy link

Hi all, i had a problem with recommended configuration file modsecurity.conf . I need last protect config for this times :)
Had a new file to improve on my modsecurity waf configuration?
Only use on our DMZ.

Thanks in advice.

@airween
Copy link
Member

airween commented Apr 25, 2025

Sorry to say, but I'm not sure I understand what do you want to achieve. Could you explain your issue more clearly?

@Max131412
Copy link
Author

Sorry, I'm testing to implement the WAF to monitor our internal web applications. I've installed and activated it with the generic configuration modsecurity.comf, and I can see the log files testing with nmap and stress the apache server :) but I'd like to know how to fine-tune the filtering. I also want to know if it can be integrated with a graphical environment. Thanks in advance.

@airween
Copy link
Member

airween commented Apr 25, 2025

ModSecurity (both mod_security2 and libmodsecurity3) is "just" an engine. If you want to protect your application/infrastructure, you must install a rule set. We prefer CRS. Or if you don't want to use any rule set, you can write your own rules - see the documentation: (it depends on which version you use)

I also want to know if it can be integrated with a graphical environment.

I know only one GUI: modseccfg, but I think it's a bit hard to use - you should give a try.

@Max131412
Copy link
Author

Sorry step by step that this web at the last step.. i have this error when restart apache sudo apache2ctl -t
AH00526: Syntax error on line 23 of /etc/modsecurity/modsecurity.conf:
ModSecurity: Found another rule with the same id.
Do you know about this error?
Thanks :)

@airween
Copy link
Member

airween commented Apr 25, 2025

ModSecurity: Found another rule with the same id.
Do you know about this error?

Probably you included a rule/config file more than once.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants