Access rules take effect before the firewall checks a request. You will find them in the Access and Rate limits tabs. As everywhere, saving creates a draft, which takes effect with Apply.
Global blocklists
Regardless of your rules, the proxy servers drop traffic from addresses and networks on global blocklists of known abuse IPs - such as botnets, scanners and attack sources, for IPv4 and IPv6. The lists are continuously updated and take effect at network level. You do not need to configure anything for this.
IP rules
In the IP rules sub-tab you create allow and block rules for individual addresses or networks in CIDR notation (IPv4 from /8, IPv6 from /32):
- Allow: Allowed addresses are not checked by the firewall, country filter or rate limits. Only for your own trusted addresses, such as your office or your monitoring.
- Block: All requests from this address are rejected (
SC-403-IP).
With Valid until you set an expiry date for a rule - after that it is removed automatically. Up to 200 IP rules are possible per site.
Allow rules and access protection
An IP allow rule does not lift access protection. For protected areas, enter the address in the access protection itself - see Protecting areas with a password or IP.
Countries and network operators (ASN)
In the Countries sub-tab you choose: All countries, Allow selected only or Block selected. Rejected requests receive SC-403-GEO.
ShieldCache determines the country and network with a local database that is updated regularly - the IP address does not leave the proxy for this. VPNs, proxies and Tor appear with the country of their server, mobile networks sometimes with the country of the network operator. The country filter protects against mass attacks, but does not replace access control.
The Network operator (ASN) sub-tab works in exactly the same way, only based on the visitor's network, such as that of a data centre or mobile operator. Enter ASNs as numbers, for example 3320 or AS3320, up to 100. IP allow rules take precedence. Blocked networks receive SC-403-ASN.
Use “Allow selected only” with care
Search engines, payment services and monitoring often access your site from other countries and networks. If necessary, allow such services with an IP allow rule, otherwise they will be rejected too.
Rate limits
Rate limits restrict how often a visitor may call a path within a time window - for example login, forms or interfaces. Counting is per visitor IP; above the limit, the visitor receives the error page SC-429-RATE.
- Open the Rate limits tab.
- Choose a template - Login, API, Form or Checkout - or enter a path yourself, for example
/wp-login.php. - Choose Exactly this path or Starts with.
- Set the limit: requests (1 to 10,000) per time window (1 to 3600 seconds). Below the form, a sentence explains how the rule works.
- Click Add rate limit and then Apply.
How many paths you can use depends on your plan; usage applies to the whole project. You can book packs of five more paths under Plan & options.
In the Log sub-tab you can see how often and from where a limit took effect: time, reference, rule, country, IP, method and address, plus the most frequent countries and networks of the last 24 hours.
Captcha check instead of a block
With the captcha check, visitors see a short check instead of an error page for the selected blocks. Anyone who solves it can continue. This lets you slow down bots without locking out real visitors.
- Open Access > Captcha check and turn on Switch on captcha check.
- Choose the triggers under Check instead of block for: rate limit, country filter, network operator (ASN) and light firewall hits. Light hits are those below the threshold for the anomaly score, 3 to 25 (default 10).
- Set the validity after a passed check, 5 to 240 minutes. For this period, the selected blocks do not apply to this visitor.
- Save and apply. The check only works in the “Active” operating mode.
Hard blocks always remain: strong firewall hits, IP blocks, file protection, size limit, maintenance and suspension of the site. Please note: anyone who has solved the check is not subject to any rate limit of this site for the selected time.
The check runs via CaptchaCore, our own captcha service: verification and database run on our own servers in Germany, without cookies, without storage in the browser and without tracking. There are no picture puzzles. IP addresses are only processed in shortened or hashed form. Find out more at captchacore.eu.
Below the settings, a preview shows what the check page looks like for your visitors - switchable per trigger, for desktop and mobile.
The statistics show under “Captcha checks” how often visitors were sent to the check and how many passed it. Redirects to the check do not count as blocked.