Skip to main content
Version: 2.0.12

CorazaWAF

opencli waf command can be used to enable/disable CorazaWAF on the server, enable/disable WAF per domain, view rules, view statistics, etc.

Status​

opencli waf status
Example output
# opencli waf status
CorazaWAF is ENABLED

Enable​

To enable the WAF and ensure it is used for new domains, run:

Response body inspection is turned off (SecResponseBodyAccess Off in /etc/openpanel/caddy/coraza_rules.conf), since buffering every HTML page for the CRS data-leakage checks adds around 230 ms per page.

This also disables OWASP CRS rulesets for stacks OpenPanel doesn't use or rarely hosts, by renaming them to .conf.disabled: REQUEST-944-APPLICATION-ATTACK-JAVA, RESPONSE-952-DATA-LEAKAGES-JAVA, RESPONSE-954-DATA-LEAKAGES-IIS and RESPONSE-956-DATA-LEAKAGES-RUBY. They can be re-enabled from OpenAdmin > Security > CorazaWAF.

opencli waf enable
Example output
# opencli waf enable
Downloading Coraza rules..
...
Downloading OWASP CRS..
Cloning into '/etc/openpanel/caddy/coreruleset'...
Disabling rulesets not used by the stack..
- Disabled ruleset REQUEST-944-APPLICATION-ATTACK-JAVA
- Disabled ruleset RESPONSE-952-DATA-LEAKAGES-JAVA
- Disabled ruleset RESPONSE-954-DATA-LEAKAGES-IIS
- Disabled ruleset RESPONSE-956-DATA-LEAKAGES-RUBY
Enabling WAF module..
Setting container image 'openpanel/caddy-coraza'..
Restarting Web Server to use the new image with CorazaWAF..
...
CorazaWAF is ENABLED

Disable​

To completely disable the WAF for all existing domains and prevent it from being applied to new domains, run:

opencli waf disable
Example output
# opencli waf disable
Checking if CorazaWAF is used by any user domains..
WARNING: WAF is still active on some domains:
- example.com
- example.net
Do you really want to disable WAF protection on these domains and stop using Coraza WAF on the server? [y/N]: y
Disabling Coraza WAF...
Disabling WAF module...
CorazaWAF is DISABLED: 'waf' module is not enabled in OpenAdmin > Settings > Modules.)

Add -y to skip the confirmation prompt:

opencli waf disable -y
Example output
# opencli waf disable -y
Checking if CorazaWAF is used by any user domains..
WARNING: WAF is still active on some domains:
- example.com
- example.net
Disabling Coraza WAF...
Disabling WAF module...
CorazaWAF is DISABLED: 'waf' module is not enabled in OpenAdmin > Settings > Modules.)

Domain​

Status​

Check if CorazaWAF is enabled for domain:

opencli waf domain <DOMAIN_NAME>
Example output
# opencli waf domain example.com
SecRuleEngine is set to On for domain example.com

Enable​

Enable WAF for a domain:

opencli waf domain <DOMAIN_NAME> enable
Example output
# opencli waf domain example.com enable
SecRuleEngine On is now set for domain example.com

Disable​

Disable WAF for a domain:

opencli waf domain <DOMAIN_NAME> disable
Example output
# opencli waf domain example.com disable
SecRuleEngine Off is now set for domain example.com

Update​

Update OWASP CRS:

opencli waf update

Rulesets disabled with a .conf.disabled file stay disabled after the update, even if the update brings back the original file.

Example output
# opencli waf update
- Excluding disabled ruleset rules/REQUEST-944-APPLICATION-ATTACK-JAVA.conf
...
Updating OWASP CRS..
- Kept ruleset RESPONSE-952-DATA-LEAKAGES-JAVA.conf disabled
Update successful.

Update Log​

View update log for OWASP CRS:

opencli waf update log
Example output
# opencli waf update log
3f2c1a9 Merge pull request #4012 from coreruleset/fix-942440-fp
8d71b0e fix(942440): reduce false positives
...

IDs​

List all rule IDs from all enabled sets:

opencli waf ids
Example output
# opencli waf ids
/etc/openpanel/caddy/coreruleset/rules/REQUEST-901-INITIALIZATION.conf:901001
/etc/openpanel/caddy/coreruleset/rules/REQUEST-901-INITIALIZATION.conf:901100
...

Tags​

List all rule tags from all enabled sets:

opencli waf tags
Example output
# opencli waf tags
/etc/openpanel/caddy/coreruleset/rules/REQUEST-913-SCANNER-DETECTION.conf:application-multi
/etc/openpanel/caddy/coreruleset/rules/REQUEST-913-SCANNER-DETECTION.conf:attack-reputation-scanner
...

Stats​

Get stats from the log.

Country​

opencli waf stats country
Example output
# opencli waf stats country
2000 US
1501 DE
1033 BE
809 SG
705 SC
606 ID
603 IN
505 NL
500 RS
209 CH
109 FR
108 PY
102 BG
70 CA

IP​

opencli waf stats ip
Example output
# opencli waf stats ip
11069 154.83.103.102
9038 154.83.103.15
9038 154.83.103.111
9038 154.83.103.106
7007 154.83.103.19
7007 154.83.103.109
4069 154.83.103.202
4069 154.83.103.10
4062 108.162.221.121
4055 154.83.103.14

Path​

opencli waf stats path
Example output
# opencli waf stats path
1308 /modules/younitedpay/logo.png
707 /.git/config
608 /.env
304 /.git/HEAD
301 /wp-content/plugins/WordPressCore/include.php
301 /php/how-to-fix-file_get_contents-wrapper-is-disabled-error-in-php/
204 /wp-includes/images/include.php
203 /wp-includes/widgets/include.php
201 /.aws/credentials
109 /wp-content/themes/include.php

Agent​

opencli waf stats agent
Example output
# opencli waf stats agent
10400 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
1909 Mozlila/5.0 (Linux; Android 7.0; SM-G892A Bulid/NRD90M; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/60.0.3112.107 Moblie Safari/537.36
1308 Go-http-client/2.0
809 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36 Edg/134.0.0.0
702 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/134.0.0.0 Safari/537.36
610 Mozilla/5.0 (Windows NT 10.0; WOW64) Gecko/20060309 Firefox/22.0
600 Mozilla/5.0 (Macintosh; Intel Mac OS X 11_8_4) Gecko/20052101 Firefox/22.0
544 Mozilla/5.0
371 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36 OPR/117.0.0.0
350 Mozilla/5.0 (Windows; U; MSIE 9.0; Windows NT 10.0; Trident/5.0; WOW64)

Hourly​

opencli waf stats hourly
Example output
# opencli waf stats hourly
14 2025/04/14 00
14 2025/04/14 10
7 2025/04/14 19
7 2025/04/15 18
7 2025/04/15 22
7 2025/04/16 00
14 2025/04/16 10
14 2025/04/16 11
7 2025/04/17 04
7 2025/04/17 07
7 2025/04/17 12
7 2025/04/18 01
7 2025/04/18 06
7 2025/04/18 07
7 2025/04/18 10
7 2025/04/18 19
469 2025/04/20 07
14 2025/04/20 08
7 2025/04/20 14
14 2025/04/20 18
7 2025/04/21 15
14 2025/04/22 05

Request​

opencli waf stats request
Example output
# opencli waf stats request
1803 POST /xmlrpc.php HTTP/1.1
1408 POST /xmlrpc.php HTTP/2.0
1038 GET /modules/younitedpay/logo.png HTTP/2.0
608 GET /.git/config HTTP/1.1
641 GET /.env HTTP/1.1
553 POST /api/discussions/137 HTTP/1.1
334 POST /api/discussions/128 HTTP/1.1
324 GET /.git/HEAD HTTP/1.1
301 POST /wp-comments-post.php HTTP/1.1
214 POST //xmlrpc.php HTTP/2.0

Count​

Display total number of records in the WAF audit log:

opencli waf count
Example output
# opencli waf count
12408