Rules Confusion

Community support forums for the free/delayed modsecurity rules feed. There is no such thing as a bad question here as long as it pertains to using the delayed modsecurity rules feed. Newbies feel free to get help getting started or asking questions that may be obvious.
jec6jec6
New Forum User
New Forum User
Posts: 1
Joined: Wed Jul 15, 2009 2:26 am

Rules Confusion

Unread post by jec6jec6 »

I have a question regarding the ASL rules and the modsecurity core ruleset that is currently available.
1. Do I need to use the core ruleset and ontop of that add the ASL rules
2. If not Does the ASL rules cover all the things contained in the core ruleset?

Thanks
faris
Long Time Forum Regular
Long Time Forum Regular
Posts: 2321
Joined: Thu Dec 09, 2004 11:19 am

Re: Rules Confusion

Unread post by faris »

The ASL rules completely replace the Core ruleset and IMHO are an order of magnitude more wide ranging.

I'll let Scott or Mike comment officially though :-)

Faris.
--------------------------------
<advert>
If you want to rent a UK-based VPS that comes with friendly advice and support from a fellow ART fan, please get in touch.
</advert>
User avatar
mikeshinn
Atomicorp Staff - Site Admin
Atomicorp Staff - Site Admin
Posts: 4149
Joined: Thu Feb 07, 2008 7:49 pm
Location: Chantilly, VA

Re: Rules Confusion

Unread post by mikeshinn »

Our intention is for our rules to be all inclusive. You'll find that our rules also cover many areas that the core rules do not, such as antispam, hidden text attacks, Just In Time Patching, malware and spam blacklisting and other features. So its actually the other way around, the core rules do not cover everything and you do not need the core rules with our rules. They stand alone. If you want to use other rules, please feel free to do so (we just dont support other peoples rules, although feel free to post about them on our forums, we'll help if we can)

Our rules are also designed to work out of the box with as little expertise or tuning necessary. The core rules require tuning before you should turn them on to block attacks. So if you want rules that will stop the attacks and require as little work on your part as possible, use our rules. We're cyber security experts but we also understand hosting (Scott and I are Plesk founders) - so we know you need a product that just works - and everything we make is based on the philosophy that Security is for Everyone. We don't expect you to be an expert - thats what you pay us for - and if we can't make it work for you thats our fault and we will fix it. Security and Convenience, all in one package.

Hope that answers your questions.
Post Reply