Skip to content

Firewall

Every site is protected by the platform’s CrowdSec firewall, with no setup required. The admin’s Firewall page shows what it is blocking and lets you ban or unban IP addresses. How CrowdSec protects you explains how detection and enforcement work.

Section Shows
Active Bans The number of IPs currently banned on the platform
Community Blocklist IPs received from the CrowdSec network, synchronized every two hours
Rule Collections The detection rule sets currently active
Live Activity Security events as they happen: new bans, detections and blocklist updates
Active Bans table Each banned IP with the rule that triggered it, the time left and its source

Details on a ban shows the rule or scenario that triggered it, its source, the time left, the IP’s location, and the matched requests: the actual requests that led to the decision. Use them to tell an attack from a false positive.

Use Ban IP on the Firewall page, or click an IP address in a site’s Live Logs, which opens the same dialog with information about the address (country, network and a WHOIS link).

Field Description
IP address The address to block
Duration 1 hour, 6 hours, 24 hours, 3 days, 7 days, 30 days or permanent
Reason A note shown in the ban details

The ban takes effect on every edge node within about 15 seconds.

When a visitor reports that every page returns 403 Forbidden, their IP is likely banned.

  1. Ask for their public IP address, or find their requests in your site’s Live Logs.
  2. Find the IP in Active Bans and open Details to see why it was banned.
  3. Click Unban. Access is restored within about 15 seconds.

If the same visitor is banned again, the matched requests in the details usually show why: a misconfigured monitoring tool, a script hammering an endpoint, or a plugin generating many 404s. Fix the cause rather than unbanning repeatedly.

Platform administrators also have access to the CrowdSec dashboard, linked under Platform in the admin sidebar. It provides the full alert history with search and filters, an attack map, decision management and notifications by email or webhook.