Last updated: 2018-01-23 20:48:55PDF
CDN provides IP Blacklist&Whitelist Configuration feature which allows you to set up filtering policies for the source IPs of user requests based on your business needs to prevent various problems such as cheating and attacks from malicious IPs.
Log in to CDN Console and go to "Domain Management" page. Then click Manage button to the right of the domain name to enter the management page:
You can find IP Blacklist & Whitelist configuration in "Access control":
By default, IP blacklist & whitelist feature is disabled and no blacklist and whitelist exist.
Configuring IP Whitelist
Click Edit button and select Whitelist to configure whitelist:
Assume that a user has configured IP whitelist for domain "www.abc.com" with the following content:
This indicates that the requested content can be returned successfully only if the source IP of the request is 188.8.131.52 or matches the network segment 184.108.40.206/24. A 403 error will be returned for any request that does not meet the condition.
Configuring IP Blacklist
Click Edit button and select Blacklist to configure blacklist:
Assume that a user has configured IP blacklist for domain "www.abc.com" with the following content:
This indicates a 403 error will be returned only if the source IP of the request is 220.127.116.11 or matches the network segment 18.104.22.168/16. For any other requests, the requested content will be returned.
- IP blacklist and whitelist are not compatible with each other. You can only enable either of them at the same time;
- You can add a maximum of 100 entries, separated by line breaks (one entry per line);
- Currently, only network segments of the following formats are supported: /8, /16, /24, /32. Any other segment formats are not supported;
- When both lists are empty, it means that IP blacklist & whitelist feature is currently disabled.