Installation Guide

Learn how to deploy ModSecurity in a production-ready setup. In the video below, Owen Garrett, Head of Products at NGINX, discusses how to install the OWASP Core Rule Set (CRS) with NGINX and ModSecurity, as well as how to tune it.


Complete Installation & Compilation Instructions

For full step-by-step installation and compilation instructions, including detailed “copy and paste” recipes for building libModSecurity and its connectors on a wide range of Linux distributions, visit our official GitHub Wiki. You’ll find platform-specific guidance, dependency lists, and recommended build configurations to help you set up ModSecurity reliably and consistently.

Visit GitHub

ModSecurity and NGINX: Tuning the OWASP Core Rule Set


Configuration

Start a new installation in detection-only mode, then review and tune the generated events before enabling blocking:

# Log rule matches without blocking requests while you tune the rule set.
SecRuleEngine DetectionOnly
# Allow ModSecurity to inspect request bodies.
SecRequestBodyAccess On
# Allow ModSecurity to inspect response bodies.
SecResponseBodyAccess On

For troubleshooting, configure SecDebugLog and temporarily increase SecDebugLogLevel; high debug levels can significantly affect performance.

Source code and further technical material are available in the ModSecurity repository.