Skip to content

Manage IPDB and DDoS protection

Use cPFence v4+ IPDB Firewall & IP Tools → Settings to set IPDB Protection, DDoS Protection and Under-Attack Mode for one server, then Save. Support users need protection-setting permission.

IPDB Settings with IPDB Protection, DDoS Protection, Under-Attack Mode, selected-server context and Save.

Protection switches for one server; identifying values hidden. Select the image for full size; use browser Back to return.

For multiple servers, choose the matching Advanced Tools action, check the sidebar targets and read each result.

  1. On System Dashboard, choose the affected server scope and select DDoS & Brute-force Attacks Blocked.
  2. Check Source is DDoS & brute-force, filter the IP/country/server, then Apply filters.
  3. Read recorded counts and LAST SEEN alongside service health. Check current policy on the IPDB page before changing access.

DDoS and brute-force attackers drawer with selected-source filters and historical attack records.

Recorded DDoS and brute-force activity in Local scope. Identifying values are concealed; historical totals do not prove present blocking. Select the image for full size; use browser Back to return.

Follow the shared dashboard drawer guidance for scope, freshness, external IP links and more retained rows.

Run the intended action as root on the licensed target:

Action Command
Enable IPDB cpfence --enable-ipdb
Disable IPDB cpfence --disable-ipdb
Restart IPDB cpfence --restart-ipdb
Enable DDoS protection cpfence --enable-DDos
Disable DDoS protection cpfence --disable-DDos
Enable under-attack mode cpfence --under-attack-on
Disable under-attack mode cpfence --under-attack-off

Connection limit in System Settings defaults to 100 concurrent connections per source. Save through the settings controls. After a direct CONNECTIONS_LIMIT edit in /etc/cpfcli/config.conf, apply it with cpfence --restart-ipdb while IPDB is enabled.

Monitor incidents in IPDB summary or run cpfence --monitor-ipdb-blocks. See traffic diagnosis before treating many requests as an attack.