Control which IPs and countries can reach your organization — four related lists on one screen.
Before you start
The Manage Access Rules right.
Steps
Go to Settings → System Security → Access Blocks. There are four sections:
IP Whitelist / IP Blacklist
- Click Add (whitelist) or Block (blacklist).
- Enter an IP Address or CIDR Range (e.g.
192.168.1.100or10.0.0.0/24— IPv4 only) and an optional description. - Save. Whitelisted addresses always take priority over blacklisted ones if the same IP somehow ends up on both.
Temporary Blocks
- Click Add Temp Block.
- Enter the IP/CIDR, an optional description, a Duration, and a unit (Minutes/Hours/Days/Months/Years).
- Save. The row shows a live countdown to expiry.
- To make it permanent, click the Promote to blacklist (gavel) icon on the row instead of waiting for it to expire.
- There's no way to extend or shorten a temp block's duration after creation — only delete it or promote it.
Geo-Blocking
- Choose Block or Allow mode, then search for a country and submit.
- Read the banner carefully before adding your first allowed country: once any country is on the allow list, every other country is denied by default, regardless of the block list. With an empty allow list, every country is allowed except ones you've explicitly blocked.
- Use the swap-arrow icon on a country row to move it between Allowed and Blocked.
What you'll see
Changes apply immediately to incoming requests. See Access Blocks Explained for how these four mechanisms relate to each other and to automated detection rules.
Artículos relacionados
Otras guías que responden preguntas cercanas a esta.
Explican bloqueos de acceso
Cuatro maneras relacionadas pero distintas de controlar quién puede llegar a su organización, todo en una pantalla Configuración: IP Whitelist siempre permitido, y siempre gana si la misma dirección también está en la…
Cómo configurar las reglas de detección
Nota: no hay un botón visible de "Nueva Regla" en la interfaz de usuario actual, sólo edición, habilitando/desactivación, y borrando una regla existente. La ruta de creación existe en el código subyacente pero nada en…
Cómo revisar los registros de acceso al sistema
Nota: la tarjeta de acceso de Configuración para esto solía llamarse "comportamientos auspiciosos" que el nombre y su vieja babosa URL (?tab=sopicious-havior) son sopaleses raquílos de un nombre; la pestaña real, actual…