Blocking malicious IP addresses

Step-by-step guide to blocking malicious IPs at three levels: cPanel and DirectAdmin control panels, htaccess file, and server firewall with real-world examples and common mistakes.

6 min Updated 11 Oct 2026

Why Should Blocking Malicious IPs Be the First Step?

Every day, thousands of suspicious requests hit web servers—from port scans and attempts to access wp-login.php to brute-force attacks on SSH and MySQL. If you have checked your server logs, you have likely seen a recurring pattern: a specific IP sending dozens or hundreds of requests in short intervals. In such situations, blocking the IP is the fastest and most effective way to cut off the attacker's access.

In this article, we cover three levels of blocking: the control panel level (suitable for shared hosting users), the .htaccess file level (for sites on Apache), and the server firewall level (for those with full control over a VPS or dedicated server). Each method has its own advantages and limitations, and the right choice depends on your hosting type and access level.

Level One: Blocking IPs in the Control Panel

If you are using shared hosting, the first place to visit is the control panel. Both common control panels (cPanel and DirectAdmin) have built-in tools for this purpose.

Blocking in cPanel

In cPanel, find the IP Blocker tool under the Security section. This tool works very simply:

  1. Go to IP Blocker.
  2. In the "IP Address or Domain" field, enter the desired address. You can enter a full IP such as 185.220.101.34 or a range like 185.220.101.
  3. Click Add.

Important note: If you enter only one IP, exactly that IP will be blocked. If you enter the first three octets (e.g., 185.220.101.), the entire Class C subnet will be blocked, which can include 254 IPs. This is useful for completely blocking a malicious range, but be careful not to lose legitimate users who might be in the same range.

Blocking in DirectAdmin

In DirectAdmin, the path is slightly different:

  1. From the main menu, go to Extra Features.
  2. Select IP Blocking.
  3. Enter the IP or range and click Add.

DirectAdmin also allows you to define a custom error message for blocked users. This message is usually displayed as 403 Forbidden.

Common mistake: Many users only block the attacker's IP in the control panel but forget that attacks often come from multiple different IPs. Before blocking, be sure to review the access logs and identify the attack patterns. If attacks come from 5 different IPs, block them all at once.

Level Two: Blocking IPs with htaccess

If your site runs on Apache or LiteSpeed, the .htaccess file is a powerful tool for access control. This method works independently of the control panel and is also useful for sites running on a virtual server (VPS) with root access.

Basic Syntax

To block a specific IP, add the following code to the end of the .htaccess file in the site's root directory:

<RequireAll>
    Require all granted
    Require not ip 185.220.101.34
</RequireAll>

If you want to block multiple IPs, you can add multiple Require not ip lines:

<RequireAll>
    Require all granted
    Require not ip 185.220.101.34
    Require not ip 203.0.113.7
    Require not ip 198.51.100.0/24
</RequireAll>

Note that 198.51.100.0/24 blocks an entire range. This syntax is supported in Apache 2.4 and later.

Legacy Method (Compatible with Apache 2.2)

If your server still uses Apache 2.2 (which is not recommended), the syntax is different:

Order Allow,Deny
Allow from all
Deny from 185.220.101.34
Deny from 203.0.113.7

This method also works in Apache 2.4 but is deprecated. If possible, use the new syntax.

Blocking Based on User-Agent

Sometimes an attacker uses a specific tool with a recognizable User-Agent. You can also block these tools:

<IfModule mod_rewrite.c>
RewriteEngine On
RewriteCond %{HTTP_USER_AGENT} (nikto|sqlmap|masscan) [NC]
RewriteRule .* - [F,L]
</IfModule>

This code blocks well-known security scanning tools such as nikto and sqlmap. But be careful: some search engines also have their own User-Agents, and you should not accidentally block them.

Common mistake: Placing the blocking code in the root site's .htaccess only applies to that domain. If you have multiple domains on one host, you must place the code in each domain's .htaccess separately. Also, if your site uses nginx, the .htaccess file does not work at all, and you must use the firewall method.

Level Three: Blocking IPs in the Server Firewall

If you have a dedicated server or VPS, the best blocking level is the firewall. This method stops the request before it reaches the web server and does not create additional load on CPU and memory.

Using iptables (Classic Method)

To block an IP with iptables:

iptables -A INPUT -s 185.220.101.34 -j DROP

To block an entire range:

iptables -A INPUT -s 198.51.100.0/24 -j DROP

To save the rules (so they persist after reboot):

iptables-save > /etc/iptables/rules.v4

To delete a rule, first find its line number:

iptables -L INPUT --line-numbers

Then delete the desired rule:

iptables -D INPUT 3

Using UFW (Simpler Method)

If you are using Ubuntu or Debian, ufw provides a simpler interface to iptables:

ufw deny from 185.220.101.34

To block a range:

ufw deny from 198.51.100.0/24

To check active rules:

ufw status numbered

And to delete rule number 2:

ufw delete 2

Using fail2ban for Automatic Blocking

Manual blocking is good, but if attacks are continuous, the fail2ban tool can automatically detect and block offending IPs. This tool monitors logs from SSH, Apache, Nginx, and many other services.

Basic installation and setup:

apt install fail2ban   # on Debian/Ubuntu
yum install fail2ban   # on CentOS/RHEL

Then create a local configuration file:

nano /etc/fail2ban/jail.local

And add the following content:

[sshd]
enabled = true
port = ssh
maxretry = 3
bantime = 3600

[apache-auth]
enabled = true
port = http,https
maxretry = 5
bantime = 3600

These settings mean: after 3 failed SSH attempts, the IP is blocked for 1 hour, and after 5 failed attempts to access a protected Apache section, the same penalty is applied.

Common mistake: Blocking your own IP! If you connect to the server from a dynamic IP (such as home internet), you might block yourself after your ISP changes your IP. Before applying a rule, be sure to check your current IP, and if necessary, use ufw allow from YOUR_IP.

Which Method Should You Choose?

The choice of IP blocking method depends on your situation:

  • Shared hosting: Use the control panel. It is simple and does not require deep technical knowledge.
  • Site on VPS with Apache: A combination of .htaccess for the site and ufw for the server gives the best results.
  • High-traffic server: Definitely use the firewall. Blocking at the web server level consumes resources.
  • Continuous attacks: Set up fail2ban so you no longer have to manually block IPs every day.

Summary and Final Tips

Blocking malicious IPs is an essential skill for every site administrator. With the three methods covered in this article, you can cover everything from the simplest (control panel) to the most advanced (firewall) level. Remember:

  1. Before blocking, review the logs and make sure the IP is truly malicious.
  2. Block large ranges with caution; you might lose real users.
  3. Test firewall rules after every change to ensure your site remains accessible to regular users.
  4. For long-term protection, use a combination of manual blocking and automated tools like fail2ban.

If your server is under heavy attacks and managing security manually has become difficult, you can use server management services and managed firewalls offered by some hosting providers like ServerNet so that a technical team monitors your infrastructure security around the clock. But in any case, knowing these techniques helps you react quickly in emergency situations.

Was this page helpful?