Moodle does not work with WAF

Moodle does not work with WAF

Maddy Fudən -
Number of replies: 2

Anyone know why Moodle does not work with cloud WAF.

Is there any app variant that supports cloud WAF?

We need WAF because getting attacks all over the world especially Russia is rather common.

Moodle got any plan to consider to develop a version that is compatible to OAWSP security model, so more people worldwide will use it too.


Any Expert know how to solve this problem.


Orta qiymət: -
In reply to Maddy Fu

Re: Moodle does not work with WAF

Mathieu Petit-Clairdən -
Core developers istifadəçinin şəkili Moodle HQ istifadəçinin şəkili MoodleCloud team istifadəçinin şəkili Plugin developers istifadəçinin şəkili Testers istifadəçinin şəkili
Hi Maddy,

I think this is perhaps more a question for the Moodle core developpers, not so much for MoodleCloud itself. I can definitely say that MoodleCloud is making use of a "web application firewall", even though that's not part of Moodle itself (neither should it, imho) but this might not be what you mean.

The short explanation found on https://www.owasp.org/index.php/Web_Application_Firewall isn't quite enough to understand precisely what you are after. Can you explain a bit more what you are trying to achieve and what's missing?

This message will most probably be moved to a forum more oriented towards Moodle development, since it's not about a MoodleCloud support question.

Mathieu
In reply to Maddy Fu

Re: Moodle does not work with WAF

Michael Hawkinsdən -
Core developers istifadəçinin şəkili Moodle HQ istifadəçinin şəkili Particularly helpful Moodlers istifadəçinin şəkili Peer reviewers istifadəçinin şəkili Testers istifadəçinin şəkili
Hi Maddy,

Is there something specific you are trying to achieve with a WAF that you are having trouble setting up? I don't think that there's something in Moodle specifically that would prevent you from using a cloud WAF.

Which of OWASP's models are you referring to? Is there something in particular you think we are not doing that we should be?

Thanks,

Mick