{{define "title"}}Rules{{end}} {{define "page"}}rules{{end}} {{define "content"}}
| File Name | Type | Size |
|---|---|---|
| Loading... | ||
CSM custom ModSecurity rules (900000-900999) can escalate to nftables firewall blocks after repeated denies. Add rule IDs here to disable escalation - the ModSecurity deny (403) still applies, but CSM won't block the IP at the firewall level.
Suppression rules hide matching findings, stop their email/webhook alerts, and stop file, process and account remediation for them. They do not stop IP blocking or challenges; allowlist an address on the Threat page instead. Rules are stored in state, not in rule files, so they survive rule updates.