Skip to content
  • GDPR-compliant
  • 100% hosting in Germany
  • Personal contact
  • Support included
  • Provisioning within 24 hours
ShieldCache 5 min read

Access rules: IP rules, countries, network operators, rate limits and captcha check

Access rules take effect before the firewall checks a request. You will find them in the Access and Rate limits tabs. As everywhere, saving creates a draft, which takes effect with Apply.

Global blocklists

Regardless of your rules, the proxy servers drop traffic from addresses and networks on global blocklists of known abuse IPs - such as botnets, scanners and attack sources, for IPv4 and IPv6. The lists are continuously updated and take effect at network level. You do not need to configure anything for this.

IP rules

In the IP rules sub-tab you create allow and block rules for individual addresses or networks in CIDR notation (IPv4 from /8, IPv6 from /32):

  • Allow: Allowed addresses are not checked by the firewall, country filter or rate limits. Only for your own trusted addresses, such as your office or your monitoring.
  • Block: All requests from this address are rejected (SC-403-IP).

With Valid until you set an expiry date for a rule - after that it is removed automatically. Up to 200 IP rules are possible per site.

IP allowlist and blocklist with the form for a new rule
An allow rule for the office address, optionally time-limited and with a note.

Allow rules and access protection

An IP allow rule does not lift access protection. For protected areas, enter the address in the access protection itself - see Protecting areas with a password or IP.

Countries and network operators (ASN)

In the Countries sub-tab you choose: All countries, Allow selected only or Block selected. Rejected requests receive SC-403-GEO.

Country filter with the modes All countries, Allow selected only and Block selected
The country filter with its three modes.

ShieldCache determines the country and network with a local database that is updated regularly - the IP address does not leave the proxy for this. VPNs, proxies and Tor appear with the country of their server, mobile networks sometimes with the country of the network operator. The country filter protects against mass attacks, but does not replace access control.

The Network operator (ASN) sub-tab works in exactly the same way, only based on the visitor's network, such as that of a data centre or mobile operator. Enter ASNs as numbers, for example 3320 or AS3320, up to 100. IP allow rules take precedence. Blocked networks receive SC-403-ASN.

Filter by network operator (ASN)
The network operator (ASN) filter with the same three modes as the country filter.

Use “Allow selected only” with care

Search engines, payment services and monitoring often access your site from other countries and networks. If necessary, allow such services with an IP allow rule, otherwise they will be rejected too.

Rate limits

Rate limits restrict how often a visitor may call a path within a time window - for example login, forms or interfaces. Counting is per visitor IP; above the limit, the visitor receives the error page SC-429-RATE.

  1. Open the Rate limits tab.
  2. Choose a template - Login, API, Form or Checkout - or enter a path yourself, for example /wp-login.php.
  3. Choose Exactly this path or Starts with.
  4. Set the limit: requests (1 to 10,000) per time window (1 to 3600 seconds). Below the form, a sentence explains how the rule works.
  5. Click Add rate limit and then Apply.

How many paths you can use depends on your plan; usage applies to the whole project. You can book packs of five more paths under Plan & options.

Rate limits with a rule, its hits and the templates
Rate limits with hits for the last 24 hours and 7 days - a click opens the rule's log.

In the Log sub-tab you can see how often and from where a limit took effect: time, reference, rule, country, IP, method and address, plus the most frequent countries and networks of the last 24 hours.

Rate limit log with a summary of the last 24 hours
The rate limit log with a summary of the last 24 hours.

Captcha check instead of a block

With the captcha check, visitors see a short check instead of an error page for the selected blocks. Anyone who solves it can continue. This lets you slow down bots without locking out real visitors.

  1. Open Access > Captcha check and turn on Switch on captcha check.
  2. Choose the triggers under Check instead of block for: rate limit, country filter, network operator (ASN) and light firewall hits. Light hits are those below the threshold for the anomaly score, 3 to 25 (default 10).
  3. Set the validity after a passed check, 5 to 240 minutes. For this period, the selected blocks do not apply to this visitor.
  4. Save and apply. The check only works in the “Active” operating mode.
Captcha check settings with triggers and validity
Captcha check with the triggers and the validity after a passed check.

Hard blocks always remain: strong firewall hits, IP blocks, file protection, size limit, maintenance and suspension of the site. Please note: anyone who has solved the check is not subject to any rate limit of this site for the selected time.

The check runs via CaptchaCore, our own captcha service: verification and database run on our own servers in Germany, without cookies, without storage in the browser and without tracking. There are no picture puzzles. IP addresses are only processed in shortened or hashed form. Find out more at captchacore.eu.

Below the settings, a preview shows what the check page looks like for your visitors - switchable per trigger, for desktop and mobile.

Preview of the check page that visitors see instead of an error page
The preview of the check page. On the real page, the CaptchaCore check field appears.

The statistics show under “Captcha checks” how often visitors were sent to the check and how many passed it. Redirects to the check do not count as blocked.

Was this article helpful?

New to SpeedIT Solutions?

Hosting where you know someone.

What you are reading here is what we put into practice for our customers every day. Based in Isernhagen since 2009 - with dedicated contact persons rather than a call centre.

  • 100% hosted in Germany
  • GDPR-compliant
  • Dedicated contact person
  • Provisioning within 24 hours
4.9 88 reviews on Expeero

SpeedIT äussert empfehlenswert

Wir sind sehr zufrieden mit der Betreuung durch SpeedIT & unsere Webseite ist bei diesem günstigen Webhosting Tarif auch sehr schnell geladen/erreichbar. Alles in Allem 10/10
CorneliaRecommends us · 08/04/2025

100 % recommend us · Expeero

All reviews on HOSTtest (opens in a new window)

You might also be interested in:

Personal support

Of course, our support team is also happy to assist you personally. If you cannot find what you are looking for in our knowledge base or require personalised support, please do not hesitate to contact us. We’re here to help you and to ensure that your experience with our products and services is as smooth and enjoyable as possible.