• We value your experience with Plesk during 2024
    Plesk strives to perform even better in 2025. To help us improve further, please answer a few questions about your experience with Plesk Obsidian 2024.
    Please take this short survey:

    https://pt-research.typeform.com/to/AmZvSXkx
  • The Horde webmail has been deprecated. Its complete removal is scheduled for April 2025. For details and recommended actions, see the Feature and Deprecation Plan.
  • We’re working on enhancing the Monitoring feature in Plesk, and we could really use your expertise! If you’re open to sharing your experiences with server and website monitoring or providing feedback, we’d love to have a one-hour online meeting with you.

mod_security making server slow

G

gizmo_24

Guest
After installing mod_security with the total ruleset I noticed that the server gets really slow and sometimes it even doesn't have the resources left for an ssh login :/

Removing mod_security makes the server run fine again.

Does anyone have suggestions on how to improve the mod_security configuration? Maybe a "lite" ruleset?

Running Plesk 7.5.4 on FreeBSD 4.10 with Apache 1.3.33
 
What are your server hardware specs? I have even run mod_security with all 10 rulesets on a Celeron 2.4 with 512MB without having any noticeable slowdowns. I have RH9, Apache 2 on the server. You can always pick and choose which rulesets to use, you do not have to run all of them.
 
the full ruleset is massive.

disable badips, blacklist and blacklist2, and see how it goes, the difference should be huge, while maintaining the same level of appllication security.
 
Back
Top