Skip to content

Add or remove an ASN block

An ASN identifies a network operator. Blocking it in cPFence v4+ can affect all of its retrieved IP ranges.

Blacklist ASN form with ASN input, Blacklist ASN button and sidebar bulk targets.

Check the network and target servers before blocking an ASN. Select the image for full size; use browser Back to return.
  1. Identify the abusive source IP and its ASN using a WHOIS lookup.
  2. Open IPDB Firewall & IP Tools → Advanced Tools → Blacklist ASN.
  3. Check the sidebar targets, enter ASN such as AS64500, and confirm Blacklist ASN.
  4. Read every target’s output and check the resulting policy. Provider failures or unavailable servers can leave partial coverage.
  1. Open IPDB Firewall & IP Tools → Advanced Tools → Remove blacklisted ASN.
  2. Check the same target servers used for the block and enter that ASN.
  3. Click Remove ASN, then read each server’s final output. An unavailable server or missing stored blocklist needs attention; submitting the request does not prove every target is unblocked.

Remove Blacklisted ASN form with ASN field, Remove ASN button and Local bulk targets.

Enter the ASN you previously blocked. The field is blank and shows its native placeholder; no removal has been submitted. Select the image for full size; use browser Back to return.

Support users need permanent-list permission and target-server access.

Open System Dashboard, check the server scope, then choose Advanced Tools → Show cPFence Status. Look for Blocked ASNs in the resulting status output. Check individual server results when reviewing several targets.

Dashboard Advanced Tools with Show cPFence Status.

Show cPFence Status opens the selected scope's status report. This image shows the entry, not a newly requested status result. Select the image for full size; use browser Back to return.

As root on the licensed target, replace the documentation ASN:

Action Command
Block ASN cpfence --blacklist-asn AS64500
Remove ASN block cpfence --remove-asn AS64500
Read cPFence status cpfence --status

Omit the ASN argument from the block or remove command to use its interactive prompt. Supplying an ASN runs the corresponding operation without that prompt; check the value carefully first. Read the final output and use cpfence --status to inspect Blocked ASNs afterward.