Whatsapp/ Telegram: 65 97765889 Live Chat Submit Ticket   Login
Add permitted IP access to your Web Server – required by Sucuri.

Add permitted IP access to your Web Server – required by Sucuri.

To avoid attacker to bypass your website firewall from Sucuri. You need to make sure the virtual host ( the protected domain name) accessed by the permitted server IP addresses.
To do this, you restrict the access of this protected domain. Today, we will give examples on the common web servers and web hosting control panel.
For Apache server has 2 versions;
 
Apache 2.4 Server
 
<FilesMatch “.*”>
Require ip 192.88.134.0/23
Require ip 185.93.228.0/22
Require ip 2a02:fe80::/29
Require ip 66.248.200.0/22
</FilesMatch>
 
Apache 2.2 Server
 
<FilesMatch “.*”>
Order deny,allow
Deny from all
Allow from 192.88.134.0/23
Allow from 185.93.228.0/22
Allow from 2a02:fe80::/29
Allow from 66.248.200.0/22
</FilesMatch>
 
Nginx Server
 
location / {
allow 192.88.134.0/23;
allow 185.93.228.0/22;
allow 2a02:fe80::/29;
allow 66.248.200.0/22;
deny all;
# Existing NGINX rules
}
It is easy with Plesk, just insert the apache code as shown.plesk apache include
plesk vhost include
This is for cPanel
cpanel
 For IIs web server, you need to add IP and Domain restriction in Roles and features. After which you add the permitted IP addresses to the protected domain. As such, attackers cannot bypass your website firewall.
How to protect your website?

How to protect your website?

 
A website is using WordPress, Joomla, Drupal is common. There is a huge collection of plug-ins, modules, and components. Most are free can download from the internet.
 
Because open source applications are free, they are a very popular choice example a WordPress website. 6 out of 10 websites are using WordPress. The installation script is available on the most popular hosting panel. A few click away, WordPress website will be ready for you
 
But do you know these websites are hackable? The vulnerabilities are in these open source CMS. Because the code on the CMS is readable by anyone. The bad guys will find its loopholes and exploit them.
 
So it is common to hear from someone, he or she has a hacked WordPress website. Can we protect it? Do we need to install a costly appliance?  In the past, engineers installed expensive equipment for combat web intrusion. Never think that the web protection existed with your web hosting which is not the case. In this modern world, cloud web protection is available at an affordable price.
 
There are 2 similar website protection services can do the job., Cloudflare, and Sucuri. Both are available at Vastspace. They have the same goal to filter any known or even suspicious malicious activities. Starts with as little as USD 20, you have CDN to speed up connections to your website and protects them at the same time. Not limited to DDOS attacks itself.
 
Cloudflare has more POPs than Sucuri. The connection to your website from many places is faster. But this is numbers on paper. Many cases, you cannot tell the difference because they are in milliseconds. I have tried both, they offered protection but I like Sucuri more.
 
sucuri cpsucuri scanI have a trial service on the Sucuri Website Firewall PRO and monitoring. From the control panel, you get to see the website health status after you have logged in. The information is something you will not have in Cloudflare. They provide you with an overview of the website health. Spamhaus status is good,  can use as a reference on your mail server RBL if they hosted together. Also, you can adjust the scan interval as low as 6 hours on the scan or scan daily as a routine.
 
sucuri advanceAt the website firewall, you will get an overview of allowed and blocked traffic. More useful options like access control,  security, performance, and SSL on the settings. For Cloudflare, I’m overwhelmed with the features. Most layman will want to pay you to solve their problem. After the initial setup, they hardly log in to tweak the settings. So, I felt that some of this settings might be too much for them to digest. On Sucuri, most essential settings are available. Except that you might want to have a closer look at advance security option and protected pages at access control. These are good options if you have a WordPress or Joomla website if you want to protect sensitive URL.
 
But, there is a con on both setups. If they are not setup correctly, attackers can bypass this firewall. Eventually, your website is not protected. So, make sure you talk to a certified engineer.
Also, like your FTP, email service, webmail, and control panel can ruin too. Make sure you check these service and ask if there is any workaround.
Feel free to write to [email protected] if you have questions about the 2 services. As their partner, we are glad to assist you.