Adding an Item to the Blacklist or Whitelist
After EIP protection is enabled, all access is allowed by default. You can configure blacklist or whitelist rules to block or allow access requests from specific IP addresses.
![](https://support.huaweicloud.com/eu/usermanual-cfw/public_sys-resources/caution_3.0-en-us.png)
- For details back-to-source IP addresses, see What Are Back-to-Source IP Addresses?
- For details about how to configure protection rules, see Adding a Protection Rule.
Specification Limitations
The CFW blacklist and whitelist each allows up to 2000 items. If there are too many IP addresses to be specified, you can put them in an IP address group dedicated to the blacklist or whitelist. For more information, see Adding Custom IP Address Groups.
Impact on the System
CFW directly allows whitelisted IP addresses and segments and blocks blacklisted ones without checking. To check the access and traffic statistics of these IP addresses, search for them by following the instructions in Querying Logs.
Procedure
- Log in to the management console.
- Click
in the upper left corner of the management console and select a region or project.
- In the navigation pane, click
and choose . The Dashboard page will be displayed, as shown in Figure 1.
- (Optional) If the current account has only one firewall instance, the firewall details page is displayed. If there are multiple firewall instances, click View in the Operation column to go to the details page.
- In the navigation pane, choose Blacklist or Whitelist tab. . Click the
- Click Add. Set the address direction, IP address, protocol type, and port number. For details, see Table 1.
Table 1 Blacklist and whitelist parameters Parameter
Description
Direction
You can select Source or Destination.
- Source: The IP address or IP address group that sends data packets.
- Destination: The destination IP address or IP address group that receives data packets.
IP Address
You can configure a single IP address, consecutive IP addresses, or an IP address segment.
Protocol Type
Its value can be TCP, UDP, ICMP, or Any.
Port
If Protocol Type is set to TCP or UDP, set the ports to be allowed or blocked.
NOTE:- To specify all the ports of an IP address, set Port to 1-65535.
- You can specify a single port. For example, to allow or block the access from port 22 of an IP address, set Port to 22.
- To set a port range, use a hyphen (-) between the starting and ending ports. For example, to allow or block the access from ports 80-443 of an IP address, set Port to 80-443.
Description
Description of the blacklist or whitelist
- Click OK.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.