Support

Admin Tools

#39196 WAF Exceptions vs Site IP Allow List

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
4.3.2
PHP version
n/a
Admin Tools version
n/a

Latest post by nicholas on Thursday, 13 July 2023 02:52 CDT

dhillock

Hello,

I have super admin access to our website and I want to make sure that my home and office IPs are never blocked.

I  see that I can add the IP addresses to the WAF Exceptions List and the Site IP Allow List. What's the difference?

Thank you and take care.

David

P.S. I did read both parts of the manual.

nicholas
Akeeba Staff
Manager

The Site IP Allow list is a whitelist, i.e. only these IPs are allowed to access the site's administrator. Putting an IP there is not enough, you would have to enable this feature in the Configure WAF page as well. I do not recommend this option unless you have a static IP address and that place is the only place from which you will ever access your site's backend.

The IP address in the WAF Exceptions List hands "get out of jail free" cards to these IP addresses. It does not block other addresses from accessing the site's administrator. The idea here is that when these excepted IP addresses do something that would normally block the request, this won't happen. It's a way to say "hey, these IP addresses are going to be doing weird things; it's okay, please don't block them". That's what you seem to want to do.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!