Add Modsecurity NGINX WAF
-
How difficult would it be to add the Modsecurity WAF for NGINX to the standard Cloudron NGINX build? And implementing the OWASP CRS ruleset? This would give the NGINX reverse Proxy some pretty capable WAF capabilities out of the box as well
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-installation-logging/
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/
-
How difficult would it be to add the Modsecurity WAF for NGINX to the standard Cloudron NGINX build? And implementing the OWASP CRS ruleset? This would give the NGINX reverse Proxy some pretty capable WAF capabilities out of the box as well
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-installation-logging/
https://docs.nginx.com/nginx-waf/admin-guide/nginx-plus-modsecurity-waf-owasp-crs/
-
@mastadamus I don't know much about this plugin/addon for nginx, but it kinda seems to be only part of Nginx Plus, which we are not using in Cloudron. Also if that matters here, the main nginx is only used as a reverse proxy.
@nebulon said in Add Modsecurity NGINX WAF:
@mastadamus I don't know much about this plugin/addon for nginx, but it kinda seems to be only part of Nginx Plus, which we are not using in Cloudron. Also if that matters here, the main nginx is only used as a reverse proxy.
I understand. Thank you for your answer.
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login