Why Should Blocking Malicious IPs Be the First Step?
Every day, thousands of suspicious requests hit web servers—from port scans and attempts to access wp-login.php to brute-force attacks on SSH and MySQL. If you have checked your server logs, you have likely seen a recurring pattern: a specific IP sending dozens or hundreds of requests in short intervals. In such situations, blocking the IP is the fastest and most effective way to cut off the attacker's access.
In this article, we cover three levels of blocking: the control panel level (suitable for shared hosting users), the .htaccess file level (for sites on Apache), and the server firewall level (for those with full control over a VPS or dedicated server). Each method has its own advantages and limitations, and the right choice depends on your hosting type and access level.
Level One: Blocking IPs in the Control Panel
If you are using shared hosting, the first place to visit is the control panel. Both common control panels (cPanel and DirectAdmin) have built-in tools for this purpose.
Blocking in cPanel
In cPanel, find the IP Blocker tool under the Security section. This tool works very simply:
- Go to
IP Blocker. - In the "IP Address or Domain" field, enter the desired address. You can enter a full IP such as
185.220.101.34or a range like185.220.101. - Click Add.
Important note: If you enter only one IP, exactly that IP will be blocked. If you enter the first three octets (e.g., 185.220.101.), the entire Class C subnet will be blocked, which can include 254 IPs. This is useful for completely blocking a malicious range, but be careful not to lose legitimate users who might be in the same range.
Blocking in DirectAdmin
In DirectAdmin, the path is slightly different:
- From the main menu, go to Extra Features.
- Select IP Blocking.
- Enter the IP or range and click Add.
DirectAdmin also allows you to define a custom error message for blocked users. This message is usually displayed as 403 Forbidden.
Level Two: Blocking IPs with htaccess
If your site runs on Apache or LiteSpeed, the .htaccess file is a powerful tool for access control. This method works independently of the control panel and is also useful for sites running on a virtual server (VPS) with root access.
Basic Syntax
To block a specific IP, add the following code to the end of the .htaccess file in the site's root directory:
<RequireAll>
Require all granted
Require not ip 185.220.101.34
</RequireAll>
If you want to block multiple IPs, you can add multiple Require not ip lines:
<RequireAll>
Require all granted
Require not ip 185.220.101.34
Require not ip 203.0.113.7
Require not ip 198.51.100.0/24
</RequireAll>
Note that 198.51.100.0/24 blocks an entire range. This syntax is supported in Apache 2.4 and later.
Legacy Method (Compatible with Apache 2.2)
If your server still uses Apache 2.2 (which is not recommended), the syntax is different:
Order Allow,Deny
Allow from all
Deny from 185.220.101.34
Deny from 203.0.113.7
This method also works in Apache 2.4 but is deprecated. If possible, use the new syntax.
Blocking Based on User-Agent
Sometimes an attacker uses a specific tool with a recognizable User-Agent. You can also block these tools:
<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (nikto|sqlmap|masscan) [NC]
RewriteRule .* - [F,L]
</IfModule>
This code blocks well-known security scanning tools such as nikto and sqlmap. But be careful: some search engines also have their own User-Agents, and you should not accidentally block them.
.htaccess only applies to that domain. If you have multiple domains on one host, you must place the code in each domain's .htaccess separately. Also, if your site uses nginx, the .htaccess file does not work at all, and you must use the firewall method.
Level Three: Blocking IPs in the Server Firewall
If you have a dedicated server or VPS, the best blocking level is the firewall. This method stops the request before it reaches the web server and does not create additional load on CPU and memory.
Using iptables (Classic Method)
To block an IP with iptables:
iptables -A INPUT -s 185.220.101.34 -j DROP
To block an entire range:
iptables -A INPUT -s 198.51.100.0/24 -j DROP
To save the rules (so they persist after reboot):
iptables-save > /etc/iptables/rules.v4
To delete a rule, first find its line number:
iptables -L INPUT --line-numbers
Then delete the desired rule:
iptables -D INPUT 3
Using UFW (Simpler Method)
If you are using Ubuntu or Debian, ufw provides a simpler interface to iptables:
ufw deny from 185.220.101.34
To block a range:
ufw deny from 198.51.100.0/24
To check active rules:
ufw status numbered
And to delete rule number 2:
ufw delete 2
Using fail2ban for Automatic Blocking
Manual blocking is good, but if attacks are continuous, the fail2ban tool can automatically detect and block offending IPs. This tool monitors logs from SSH, Apache, Nginx, and many other services.
Basic installation and setup:
apt install fail2ban # on Debian/Ubuntu
yum install fail2ban # on CentOS/RHEL
Then create a local configuration file:
nano /etc/fail2ban/jail.local
And add the following content:
[sshd]
enabled = true
port = ssh
maxretry = 3
bantime = 3600
[apache-auth]
enabled = true
port = http,https
maxretry = 5
bantime = 3600
These settings mean: after 3 failed SSH attempts, the IP is blocked for 1 hour, and after 5 failed attempts to access a protected Apache section, the same penalty is applied.
ufw allow from YOUR_IP.
Which Method Should You Choose?
The choice of IP blocking method depends on your situation:
- Shared hosting: Use the control panel. It is simple and does not require deep technical knowledge.
- Site on VPS with Apache: A combination of
.htaccessfor the site andufwfor the server gives the best results. - High-traffic server: Definitely use the firewall. Blocking at the web server level consumes resources.
- Continuous attacks: Set up
fail2banso you no longer have to manually block IPs every day.
Summary and Final Tips
Blocking malicious IPs is an essential skill for every site administrator. With the three methods covered in this article, you can cover everything from the simplest (control panel) to the most advanced (firewall) level. Remember:
- Before blocking, review the logs and make sure the IP is truly malicious.
- Block large ranges with caution; you might lose real users.
- Test firewall rules after every change to ensure your site remains accessible to regular users.
- For long-term protection, use a combination of manual blocking and automated tools like fail2ban.
If your server is under heavy attacks and managing security manually has become difficult, you can use server management services and managed firewalls offered by some hosting providers like ServerNet so that a technical team monitors your infrastructure security around the clock. But in any case, knowing these techniques helps you react quickly in emergency situations.