It looks as “Additional Firewall Rules” applied from your plugin not reflecting within the application.
The rules which are specifically not working and were flagged as an issue during the PEN test of the application are:
* Listing of Directory Contents
* Trace and Track
* Bad Query Strings
* Advanced Character String Filter
All available under Firewall -> Advanced Firewall Rules.
These are the ones I proved do not apply properly on my Application but started to question the other functionality of the plugin.
I wonder if this plugin can conflict with others and that is why it is not working properly on my side or there might be some sort of a bug in the software itself?
Side is behind internal firewall during development phase and therefore cannot be accessed from the internet thus I have not provided the path
Thanks in advanced.
]]>I keep getting this alert on top of every page:
The last rules update for the Wordfence Web Application Firewall was unsuccessful. The last successful update check was 05/05/2020 18:14, so this site may be missing new rules added since then. You may wait for the next automatic attempt at 19/05/2020 18:20 or try to Manually Update by clicking the “Manually Refresh Rules” button below the Rules list.
I’ve clicked Manually Update link several times and it just takes time to the Wordfence dashboard page and the alert still remains there.
What else do I need to do?
]]>The last rules update for the Wordfence Web Application Firewall was unsuccessful. The last successful update check was 22. May 2019 11:14, so this site may be missing new rules added since then. You may wait for the next automatic attempt at 12. June 2019 11:15 or try to Manually Update by clicking the “Manually Refresh Rules” button below the Rules list.
But when I try to update the rules manually, I get this error:
No rules were updated. Your website has reached the maximum number of rule update requests. Please try again later.
Any idea how to fix this problem?
]]>Manual update fails, and claims it can’t connect to the wordfence site despite the diagnostics tab saying it’s fine. Automatic update has not been successful since March 9th. Time stamp stays the same. I’ve deleted rules.php, and while the file was recreated, it was a 0b, empty file and did not regenerate even after several hours. I restored my March 9th file.
Diagnostics all look good (success on connecting with the Wordfence server there).
I’ve deactivated and reactivated the plugin. It’s on the latest version 7.2.4. I’d prefer not to have to uninstall it if possible, since other people having this issue on Dreamhost seem to have no success with that approach.
I’ve done a fresh WordPress install on another domain (no content), with Wordfence, so there should be no conflicts. However, it’s also on Dreamhost, and has the same issue.
Due to the amount of people with Dreamhost having this issue, I assume it’s an issue with that host specifically that’s developed over the last 2~ weeks. I’m very willing to work with Dreamhost to get it resolved, but what do I need to ask them? “My Wordfence plugin won’t update firewall rules” doesn’t seem like it would be sufficient for them to deal with.
Thanks.
]]>“The last rules update for the Wordfence Web Application Firewall was unsuccessful. The last successful update check was March 9, 2019 11:25 pm, so this site may be missing new rules added since then. You may wait for the next automatic attempt at March 24, 2019 12:29 am or try to Manually Update by clicking the “Manually Refresh Rules” button below the Rules list.”
Attempting to “Manually Refresh Rules”, I get the following:
“Rule Update Failed
No rules were updated. Please verify you have permissions to write to the /wp-content/wflogs directory. ”
Permissions on the wflogs folder are currently 755. I have attempted to manually set them to 777 to test, and it still failed. I was able to save a test file to the folder, and remove it, without issue.
Permissions on the wflogs/rules.php file are currently 644. All attempts to update fail with the same error. Date/time on file has not changed.
Diagnostics have been sent.
]]>It catches attempted logins and bans the users, and that’s basically the problem I was having.
Sometimes there’s just too much security though.
https://www.ads-software.com/plugins/all-in-one-wp-security-and-firewall/
]]>Meaning, “If a human’s page views exceed: 240 per minute then Block It” is set, is that 240 per minute per subsite or for the entire network?
Please advise.
And thank you for the great plugin!!!
https://www.ads-software.com/plugins/wordfence/
]]>https://www.ads-software.com/plugins/wordfence/
]]>