Skip to content

Banned IPs

Banned IPs is the list of addresses and networks that are permanently blocked from sending any request to your server. Use it to manually block a source you know to be malicious (an attacker seen in your logs, an abusive range) and to remove blocks that were applied in error. Unlike the automatic, time-limited bans produced by Traffic Control, entries here stay in place until you delete them.

For addresses that were banned automatically by the security system and expire on their own, see Temporarily Banned IPs.

Banning IP Addresses

Add individual IP addresses (for example 198.51.100.7) or subnets in CIDR notation (for example 198.51.100.0/24) to the ban list. Every subsequent request from a matching source is dropped.

Unbanning IP Addresses

Delete the address from the list and save. This is also how you recover if you (or an automated rule) blocked something you shouldn’t have.

Best practices

  • Prefer permanent bans for confirmed, persistent abuse - a range that repeatedly attacks you - and let Traffic Control handle transient, opportunistic scanners automatically.
  • Ban the tightest range that stops the abuse. Blocking an overly broad subnet can catch legitimate carriers, mobile users, or remote staff who share that range.
  • Double-check before banning shared or carrier ranges - your SIP provider, remote workers on mobile networks, and cloud services often sit behind large shared blocks.
  • Keep genuinely trusted sources on the Trusted IPs list so they are never auto-banned in the first place; a manual ban here still overrides trust, so you retain full control.