With access protection you protect the whole site or an area such as /admin/ or a test environment - directly on the proxy, without adapting your application. You will find it under Access > Access protection.
The four types of protection
- Login only: The browser asks for a user name and password. Suitable if authorised users access the site from changing locations.
- Allowed IP addresses only: Only requests from the entered addresses or networks get through, all others receive an error page. No login.
- IP address or login: From allowed addresses, such as your office, without a login; from anywhere else with a user name and password.
- IP address and login: The strictest - only from allowed addresses and additionally with a user name and password.
Step by step
- Click Add protection.
- Choose the Protected area: Whole site or One path only. For a path, also choose “Exactly this path” or “Starts with”.
- Choose the Type of protection.
- For IP types, enter individual addresses or networks under Allowed IP addresses, for example
203.0.113.0/24- up to 50. With “Add my IP” you enter your current address. - Optional: a Label in the login prompt, which some browsers display.
- Click Create protection.
Creating logins
For types with a login, after saving you create users in the same dialogue under Logins - up to 20 per protection:
- Enter a user name, for example
redaktion. - Assign your own password - at least 12 characters, at least 6 different characters, not the user name - or click Generate password. A generated password has 20 characters and is shown exactly once. Copy it and pass it on securely.
- To set a password, you confirm your login to the customer area again.
Only an encrypted form (hash) is stored. A forgotten password cannot be displayed, only reset. As long as a protection with login has no login entry, applying is blocked.
Good to know
- IP allow rules from the IP rules and the captcha check do not lift access protection.
- Protected areas are never cached - every request goes to your server.
- After 20 failed attempts within one minute, ShieldCache briefly blocks logins from the same connection (error page
SC-429-SCHUTZ). - Only switch on Pass the login on to your server if your server evaluates the same login itself. Otherwise ShieldCache removes the credentials before the request reaches your server.
List and log
The list shows each protection with its area, type, addresses, logins and the rejected requests of the last 24 hours and 7 days. A click on the number opens the log under Access > Log; rejected access attempts are listed there with the types “Protection: IP” and “Protection: login”. Other addresses receive SC-403-SCHUTZ, a missing or incorrect login SC-401-LOGIN.