Overview
This step-by-step guide will help you activate the Sucuri Web Application Firewall (WAF) for your website via your Client Area. The firewall offers advanced protection against hacks, malicious traffic, and security threats by filtering connections through a secure IP and providing monitoring tools.
Access Sucuri WAF in the Client Area
- Log in to the Client Area → Cloud Services → My Hosting & Services.
- Click on Security Services – Sucuri WAF linked to your hosting plan.
- You will be redirected to the Product Details page.
Add Your Hosting IP Address
- In the General section, locate Host IP Address.
- Enter your hosting IP address in the provided field.
- Specify if it is Hosting or Backup.
- Select the appropriate Region.
- Click Add Address to save it.
Point Your Domain to Sucuri
- Update your DNS records as follows:
- Change the A Record for your domain to the Sucuri Firewall IP (TTL: 300 seconds).
- 🔍 Find the Firewall IP in your Client Area under Product Details → Overview → Sucuri Details.
- Replace the CNAME record for mail.domain.ly with an A Record pointing to your server IP.
- If the MX Record points to the main domain, change it to mail.domain.ly.
- Remove or update any AAAA records for the domain and www.domain.
- For domain aliases, update A and AAAA records to match the Sucuri Firewall IP.
Edit .htaccess to Prevent Firewall Bypass
- Wait for the domain to fully propagate.
- Log in to Client Area → Cloud Services → My Hosting & Services → Sucuri WAF.
- Go to Security → scroll to Preventing Firewall Bypass.
- Copy the code under Apache 2.4 Server.
- In your site's root directory (public_html), open or create a .htaccess file.
- Paste the code and Save.
Enable Email Reports
- In the Client Area under Security Services – Sucuri WAF, go to Email Reports.
- Toggle Send me reports by email.
- Choose Report Format and Frequency.
- Enter your Email Address and click Save.