Using IP Access Lists to protect WordPress
High performance IP access list engine allows you to protect WordPress virtually with unlimited IP addresses, networks and IP ranges in the access lists.
IP Access Lists (commonly referred to as ACLs) are intended to restrict access to vital WordPress functions, WordPress login and registration forms from unwanted computers and bots. The WP Cerber plugin supports two types of access lists: White IP Access List and Black IP Access List. Both access lists are manually managed by the website admin on the Access List settings page. Optionally an IP can be added to the White IP Access List from the Activity page.
Note: before you can start using access lists, you have to make sure that the plugin detects IP addresses correctly. How to do that – Getting Started.
Additional note if your WordPress is under CloudFlare.
By adding IP addresses to the Black IP Access List you block the ability to log into the site, submit forms and make unsafe/harmful requests to vital WordPress functionality that are protected by WP Cerber:
- Deny IP to log in to the website
- Deny IP to register on the website
- Deny IP to post comments and submit forms
- Deny IP to use WP REST API completely
- Deny IP to use XML-RPC completely
- Deny IP to access WordPress PHP scripts that usually is being used by bots and hackers: wp-login.php, wp-signup.php, wp-register.php
When you put a particular IP address, subnet or IP range on the White IP Access List you permit these IP addresses to ignore limit login attempts rules, the plugin settings and use WordPress features, that are protected by WP Cerber, without limitations:
- Allow IP to log in to the site with no limit on login attempts (if you uncheck Apply limit login rules to IP addresses in the White IP Access List in the limit login settings)
- Allow IP to bypass spam check
- Allow IP to log in if the Citadel mode is active
- Allow IP to use the registration form to register if registration is enabled in the WordPress settings
- Allow IP to use WP REST API without limitation
- Allow IP to use the XML-RPC interface without limitation
What’s the order of operations in IP Access Lists?
The White IP Access list has the highest priority and will be checked for an IP address first, then the IP will be checked against the Black IP Access List and, then the IP will be checked against the list of locked out IPs, finally WP Cerber checks particular plugin settings you have configured. That means that if a specific IP address is in the White IP Access list, it will be permitted to proceed and no further checks any kind will be performed.
Order of operations in a short list as they will be performed. If an IP is matched any of the following steps, no further checks will be performed.
- The White IP Access List allows IP unconditionally
- The Black IP Access List denies IP unconditionally
- The list of locked out (blocked) IP addresses, denies IP if in the list
- Check for a particular WP Cerber setting
Note: When you activate WP Cerber, it automatically adds your computer network, including your IP address, to the White Access list to protect you from getting locked out by chance.
Possible values for entries in IP Access Lists
- Single IPv6 address like
- Single IPv4 address like
- IPv4 address range with a dash like
192.168.1.45 - 192.168.22.165
- IPv4 CIDR like
- IPv4 subnet Class C like
- IPv4 subnet Class B like
- IPv4 subnet Class A like
FAQ about the IP Access Lists
How to grant access to a certain set of several IP address and block to the rest of the world?
- Add your IP address or a set of IPs you want to permit to log into your website to the White IP Access List.
- Add the
*.*.*.*string to the Black IP Access List.
Can an IP address from any access list be locked out and shown on the Lockouts tab?
Never. It doesn’t make sense.
Other notes about IP Access Lists for WordPress
- You cannot add the same IP address or IPv4 range to both lists.
- When you install and activate the WP Cerber plugin, it automatically adds your computer network to the White IP Access List.
- The Access List can be easily exported to a file and then be imported on another website with the WP Cerber plugin installed.
Last posts from WordPress security blog
- Development version 7.9.9 February 10, 2019
- Manage multiple WP Cerber instances from one dashboard February 4, 2019
- WP Cerber Security 7.9.7 January 11, 2019
- Registered users only mode January 8, 2019
- Development version 7.9.5 December 20, 2018