Block Direct IP Access to Your Server
Answer only on your own hostnames
Answer only on your own hostnames
Direct IP Access Blocking makes your server refuse every visit that does not use one of your sites' hostnames, for example a visit to its bare IP address. Use it when your sites sit behind Cloudflare or another CDN and the server itself should not be reachable directly.
Where: Servers › My Servers › your server › Services › Security Settings › Direct IP Access Blocking
01 · Turn it on
- Click Block Direct IP Access.
- Confirm. The line next to the button now reads Direct IP access is blocked.
To undo it, click Disable IP Blocking; the line reads Direct IP access is allowed again.
02 · What changes
- A request whose hostname matches none of your sites, over HTTP or HTTPS, gets 403 Forbidden with the text Direct IP access is not allowed.
- Requests to your sites' hostnames work as before.
Every name a site answers to must be its project's Hostname or one of its Server Aliases (project page › Edit Settings). A name that is in neither is refused too.
To limit which addresses can reach the server at all, use the firewall.
Services tab
- Services tab
- Start, stop, restart
- PHP configuration
- Cache stats
- Varnish cache
- Direct IP blocking
- WireGuard network