Add Modsecurity NGINX WAF
-
How difficult would it be to add the Modsecurity WAF for NGINX to the standard Cloudron NGINX build? And implementing the OWASP CRS ruleset? This would give the NGINX reverse Proxy some pretty capable WAF capabilities out of the box as well
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-installation-logging/
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/
-
@mastadamus I don't know much about this plugin/addon for nginx, but it kinda seems to be only part of Nginx Plus, which we are not using in Cloudron. Also if that matters here, the main nginx is only used as a reverse proxy.
-
@nebulon said in Add Modsecurity NGINX WAF:
@mastadamus I don't know much about this plugin/addon for nginx, but it kinda seems to be only part of Nginx Plus, which we are not using in Cloudron. Also if that matters here, the main nginx is only used as a reverse proxy.
I understand. Thank you for your answer.