Skip to content

Block or whitelist a user agent

Use cPFence v4+ user-agent lists for custom bot exceptions or blocks. A User-Agent string can be spoofed; it is not an authenticated identity.

Edit Configuration Files with WAF user-agent blocklist selected, its path and Save changes.

The selected user-agent blocklist on one server. File contents are concealed for privacy; the white area does not indicate an empty list. Select the image for full size; use browser Back to return.

Edit Configuration Files with WAF user-agent whitelist selected, its path and Save changes.

The separate user-agent whitelist. File contents are concealed for privacy; this is not a default or example list. Select the image for full size; use browser Back to return.
  1. Choose the target server and disable its WAF master for the editing window.
  2. Open Edit Configuration Files and choose WAF user-agent blocklist or WAF user-agent whitelist.
  3. Keep existing entries and add/remove one literal agent phrase per line in File content.
  4. Choose Save changes, read the result and reload to confirm.
  5. Enable WAF again, then check the intended request and current WAF events.

Support users need file-editing and WAF-control permissions. Root file locations are /etc/cpfcli/waf/userdata_bl_agents and /etc/cpfcli/waf/userdata_wl_agents; prefer the validated editor workflow.