Learn how to install and configure Imunify360 WAF on your AtoZNode server. Stop SQLi and XSS attacks with automated protection and easy setup steps.
6 min read
Web applications are constantly exposed to Layer 7 attacks such as SQL injection, cross‑site scripting (XSS), and malicious bots. Even a well‑coded site can become a target, and manual rule‑writing quickly turns into a maintenance nightmare. Imunify360’s Web Application Firewall (WAF) automates protection by analysing HTTP traffic in real time, blocking known attack patterns and learning from new threats.
Why Use Imunify360’s WAF?
Automatic rule updates – The WAF pulls signatures from CloudLinux’s threat‑intelligence network, keeping you protected against the latest exploits.
Low false‑positive rate – Machine‑learning models differentiate legitimate traffic from attacks, reducing the chance of blocking real users.
Integrated with other Imunify360 modules – Malware scanning, intrusion detection, and reputation checks share data, giving you a unified security dashboard.
Easy to enable – A few CLI commands or a single click in the control panel activate the firewall on a fresh VPS or dedicated server.
Prerequisites
An active AtoZNode VPS or dedicated server running a supported Linux distribution (Ubuntu/Debian or AlmaLinux/Rocky/RHEL).
Root or sudo access to the server.
Imunify360 installed (the package includes the WAF component).
Installing Imunify360 (If Not Already Present)
Ubuntu / Debian (apt)
# Update the package index
sudo apt update
# Install required utilities
sudo apt install -y curl gnupg
# Import the Imunify360 repository GPG key
curl -sSL https://repo.imunify360.com/ubuntu/KEY.gpg | sudo apt-key add -
# Add the repository (replace “focal” with your Ubuntu codename if needed)
echo "deb [arch=amd64] https://repo.imunify360.com/ubuntu focal main" \
| sudo tee /etc/apt/sources.list.d/imunify360.list
# Refresh the index and install Imunify360
sudo apt update
sudo apt install -y imunify360
This sequence adds Imunify360’s official APT repository, updates the local package list, and installs the full suite.
AlmaLinux / Rocky Linux / RHEL (dnf)
# Install required utilities
sudo dnf install -y curl gnupg2
# Import the repository GPG key
sudo rpm --import https://repo.imunify360.com/rhel/KEY.gpg
# Create a repository file (replace “8” with your major version if needed)
cat > /etc/yum.repos.d/imunify360.repo <<EOF
[imunify360]
name=Imunify360 Repository
baseurl=https://repo.imunify360.com/rhel/8/\$basearch
enabled=1
gpgcheck=1
gpgkey=https://repo.imunify360.com/rhel/KEY.gpg
EOF
# Install Imunify360
sudo dnf install -y imunify360
The DNF block creates a repository file pointing to the correct release and then installs the package.
Activating the Web Application Firewall
After installing Imunify360, the WAF is disabled by default. Enabling it requires a single command:
Common command (works on both families)
sudo imunify360-agent enable-waf
This tells the Imunify360 daemon to start the ModSecurity‑based WAF and load the default rule set.
Fine‑Tuning the WAF for Your Site
Out‑of‑the‑box protection covers most generic attacks, but you may want to adjust sensitivity, whitelist trusted IPs, or add custom rules for a particular application.
1. Adjusting Sensitivity Levels
# Show the current sensitivity (0 = low, 5 = high)
sudo imunify360-agent waf-get-sensitivity
# Set a medium level (recommended for most sites)
sudo imunify360-agent waf-set-sensitivity 3
A higher level blocks more suspicious requests but may increase false positives. Test changes on a staging environment if possible.
2. Whitelisting IP Addresses or CIDR Ranges
# Add a single IP to the whitelist
sudo imunify360-agent waf-whitelist-add 203.0.113.42
# Add a CIDR block
sudo imunify360-agent waf-whitelist-add 198.51.100.0/24
Whitelisted sources bypass all WAF checks, useful for internal monitoring tools or trusted API clients.
3. Adding Custom ModSecurity Rules
Imunify360 stores its ModSecurity configuration under /etc/imunify360. To add a rule, create a .conf file and include it in the main configuration.
# Create a custom rule file (example: block requests with a suspicious User‑Agent)
sudo tee /etc/imunify360/custom-rules.conf <<EOF
SecRule REQUEST_HEADERS:User-Agent "badbot" \
"id:100001,phase:1,deny,status:403,msg:'Blocked bad bot'"
EOF
# Ensure the custom file is included
sudo sed -i '/Include \/etc\/imunify360\/custom-rules.conf/d' \
/etc/imunify360/imunify360.conf
echo "Include /etc/imunify360/custom-rules.conf" | \
sudo tee -a /etc/imunify360/imunify360.conf
# Reload the WAF to apply changes
sudo systemctl reload imunify360
The rule above blocks any request whose User-Agent header contains “badbot”. Adjust the pattern or action to suit your needs.
4. Monitoring Logs and Alerts
Imunify360 writes WAF events to /var/log/imunify360/ims-waf.log. View recent blocks with:
sudo tail -f /var/log/imunify360/ims-waf.log
For a quick summary of blocked attacks:
sudo imunify360-agent waf-stats
The command outputs counts per attack type (SQLi, XSS, etc.) and helps you decide whether to tighten or relax rules.
Integrating the WAF with Your Control Panel (cPanel, Plesk, DirectAdmin)
If you manage multiple sites through a hosting panel, Imunify360 provides a graphical toggle:
Log in to the panel as admin.
Navigate to Imunify360 → WAF.
Use the switch to enable or disable the firewall for each domain.
Adjust sensitivity and whitelist settings via the same interface.
The panel writes the same configuration files described earlier, so manual CLI steps are not required unless you prefer scripting.
Testing Your WAF Configuration
After enabling and tuning the firewall, verify that it blocks malicious traffic without affecting legitimate users.
1. Simulate an SQL Injection
curl -I "https://yourdomain.com/index.php?id=1' OR '1'='1"
A correctly configured WAF should return 403 Forbidden and log an SQLi event.
The request should pass through even if it matches a blocked pattern, confirming the whitelist works.
3. Verify Custom Rules
curl -I -A "badbot" https://yourdomain.com/
The response should be 403 with a log entry matching the custom rule ID (100001).
Maintaining the WAF Over Time
Regular updates – Imunify360 updates its rule set automatically, but running the OS package manager weekly ensures you have the latest engine.
Review false positives – Use imunify360-agent waf-stats to spot patterns that may affect real users, then adjust sensitivity or add specific whitelists.
Backup configuration – Copy /etc/imunify360 to a safe location before major changes or OS upgrades.
Stay informed – Subscribe to CloudLinux security newsletters for announcements about new attack vectors and rule improvements.
Conclusion
Layer 7 attacks target the very logic of your web applications, and manual defenses rarely keep pace. Imunify360’s Web Application Firewall offers automated, continuously updated protection that integrates seamlessly with AtoZNode’s VPS and dedicated servers. By installing the package, enabling the WAF, and fine‑tuning sensitivity, whitelists, and custom rules, you can defend your sites against SQL injection, XSS, malicious bots, and emerging threats while maintaining a low false‑positive rate. Remember to test your configuration, monitor logs, and keep the software up to date for sustained security.