Skip to content

Edit the custom WAF IP blocklist

The cPFence v4+ WAF IP list is separate from automatic Layer7 protection and the IPDB firewall lists.

WAF IP blocklist selected in Edit Configuration Files, with its path and Save changes.

Choose the WAF request-level IP list on the intended server. File contents are concealed for privacy, not shown as an empty or default list. Select the image for full size; use browser Back to return.
  1. Choose the target server and disable its WAF master for editing.
  2. Open Edit Configuration Files → WAF IP blocklist.
  3. Keep a copy of the current list, then add or remove one valid IP address or CIDR per line.
  4. Choose Save changes, read the result and reload to verify.
  5. Enable WAF again, then check the intended request and matching event.

Support users need file-editing and WAF-control permissions. The installed list is /etc/cpfcli/waf/userdata_bl_IPs.

Disabling automatic Layer7 protection does not erase this custom list. Use IPDB policies when you intend a firewall policy rather than a WAF request rule.