IP deny
Block an IP address or range at the edge and at the server, allow an address through a blocked range, and avoid locking yourself out.
IP deny blocks traffic from an address or a range before it reaches WordPress. Open your site, then Tools, and choose the IP deny tab at the top of Tools to manage the list. IP deny works on the live environment. Avaloi enforces the list at Cloudflare and again on your site's web server.
Turn IP deny off and on
The IP deny card on the Tools tab switches the whole list off or on. Turning IP deny off keeps every entry saved, and you can still edit the list, but nobody is blocked: neither Cloudflare nor the web server uses the list until you turn it on again. While it is off, the IP deny tab leaves the top of Tools. A bookmark to the list still opens it, with IP deny is off and an Enable IP deny button. An off list also takes no room in the shared Cloudflare firewall rules.
The switch runs as a job and is recorded in User activity. Through the API, send PUT /v1/environments/{id}/tools/ip-deny with {"enabled": false} or {"enabled": true}. The MCP tool set_ip_deny_enabled does the same.
Old links to the IP deny page still work and open it under Tools.
Cloudflare rules for every site share Avaloi's Cloudflare plan, which allows a set number of firewall rules. When they are full, the tab says so and your list is enforced by the web server alone. Blocked visitors still never reach WordPress.
Block an address or range
- Open your site, then Tools, then IP deny.
- Choose Add IP addresses.
- Enter one address, or a range in CIDR form such as
203.0.113.0/24, per line. - Add a note so your team knows why, then choose Add.
Avaloi applies the rule through a job. Requests from that address or range are blocked at the edge and at the server.
Allow an address through a blocked range
Add the address with the type Always allow these addresses. An allow entry wins over a deny range that contains it, so you can block a whole network and still let one address in.
Add your current IP
In the add dialog, Add my IP address fills in the address you are using now. Use it to allow your own address before you block a range that contains it.
Avoid locking yourself out
Avaloi warns before it blocks your own address, because that locks you out of the site. Confirm only if you mean it. Through the API, a rule that would block the address you are calling from is refused unless allow_self_lockout is true.
Replace the whole list
Tick several entries and choose Remove to remove them together. The dashboard adds and removes entries in one job by replacing the whole list, and you can do the same through the API.
Limits
- Ranges wider than a /8 for IPv4 are refused.
- Ranges wider than a /32 for IPv6 are refused.
- An environment holds up to 1,000 entries.
Quick answers
I blocked myself. How do I get back in? Connect from another address or network, open IP deny, and delete the rule. If you cannot, contact support.
Does a rule block the whole site or one environment? One environment. Add the rule on each environment you want to protect.
Can I block a country? No. IP deny works on addresses and ranges. Bot protection handles automated traffic in general.
Why was my range refused? It was wider than the limit: /8 for IPv4 or /32 for IPv6. Split it into smaller ranges.
API
GET /v1/environments/{id}/ip-rulesPOST /v1/environments/{id}/ip-rulesPUT /v1/environments/{id}/ip-rulesDELETE /v1/environments/{id}/ip-rules/{rule_id}
Related
Still stuck?
Email [email protected] with your site name and what you tried, or send us a message.