Help Center> Web Application Firewall> FAQs> Protection Rule Configuration> Others> How Do I Allow Only Specified IP Addresses to Access Protected Websites?
Updated on 2023-11-30 GMT+08:00

How Do I Allow Only Specified IP Addresses to Access Protected Websites?

After you add the website to WAF, configure blacklist and whitelist rules or precise protection rules to allow only specified IP addresses to access the website. WAF then blocks all source IP addresses except the specified ones.

Configuring IP Address Blacklist and Whitelist Rules to Block All Source IP Addresses Except the Specified Ones

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click in the upper left corner and choose Web Application Firewall under Security & Compliance.
  4. In the navigation pane on the left, choose Policies.
  5. Click the name of the target policy to go to the protection configuration page.
  6. In the Blacklist and Whitelist configuration area, enable the protection.

    Figure 1 Blacklist and Whitelist configuration area

  7. Click Customize Rule. On the displayed page, click Add Rule in the upper left corner.
  8. In the Add Blacklist or Whitelist Rule dialog box, add two blacklist rules to block all source IP addresses.

    Figure 2 Blocking IP address range 1.0.0.0/1
    Figure 3 Blocking IP address range 128.0.0.0/1

  9. Click Add Rule. In the displayed Add Blacklist or Whitelist Rule dialog box, add a rule for the specified IP address or IP address range.

    For example, if you want to allow XXX.XX.2.3 to access your website, add a protection rule as shown in Figure 4.
    Figure 4 Allowing the access of a specified IP address

Configuring a Precise Protection Rule to Block All Source IP Addresses Except the Specified Ones

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Click in the upper left corner and choose Web Application Firewall under Security & Compliance.
  4. In the navigation pane on the left, choose Policies.
  5. Click the name of the target policy to go to the protection configuration page.
  6. In the Precise Protection configuration area, enable the protection.

    Figure 5 Precise Protection configuration area

  7. Click Customize Rule. In the upper left corner of the displayed page, click Add Rule.
  8. In the displayed Add Precise Protection Rule dialog box, add a protection rule as shown in Figure 6 to block all requests.

    The priority value here must be greater than that configured in Step 9 because allowing access has a higher priority than blocking access and a smaller priority value indicates a higher priority.

    Figure 6 Blocking all requests

  9. Click Add Rule. In the displayed Add Precise Protection Rule dialog box, add a rule for the specified IP address.

    For example, if you want to allow 192.168.2.3 to access the website, add a protection rule as shown in Figure 7.

    The priority value here must be smaller than that configured in Step 8 because allowing access has a higher priority than blocking access and a smaller priority value indicates a higher priority.

    Figure 7 Allowing the access of a specified IP address

    You can also add a whitelist rule for specified IP addresses or IP address range by referring to Step 9.

Others FAQs

more