All Products
Search
Document Center

Web Application Firewall:Configure IP blacklists

Last Updated:Jun 02, 2026

After you add a website to Web Application Firewall (WAF), enable IP blacklists to block requests from specific IP addresses, IP address ranges, and geographic regions.

Background

Two types of IP blacklists are available:

  • Standard IP blacklist: Blocks requests from specified IP addresses or IP address ranges.

  • Region-level IP blacklist: Blocks requests from specified countries or regions.

Prerequisites

  • Your active WAF instance is Pro, Enterprise, Ultimate Edition, or Exclusive.

    Important

    Pro and Enterprise instances support only standard IP Address Blacklist, which apply to specific IP addresses. These instances do not support a Region Blacklist, which applies to all IP addresses in a specified region.

    To use a Region Blacklist, you must have an Ultimate Edition or Exclusive instance.

  • Your website has been added to WAF. For more information, see Tutorials.

Procedure

  1. Log on to the Web Application Firewall (WAF) console. In the top menu bar, select the resource group and region for your WAF instance: Chinese Mainland or Outside Chinese Mainland.

  2. In the left navigation pane, choose Protection Config > Website Protection.

  3. On the Website Protection page, switch to the domain name to configure.切换域名

  4. Click the Access Control/Throttling tab, locate the Blacklists card, turn on the Status switch, and click Configure Now.

    Note

    WAF checks all requests to your website against the IP blacklist by default. To allow specific requests to bypass this check, configure an Access Control/Throttling whitelist. Configure an Access Control/Throttling whitelist.

  5. On the Blacklists page, configure the Blacklists and Region Blacklist sections.

    • Blacklists: Enter the IP addresses to block, separated by commas (up to 200), and click Save.

    • Region Blacklist: On the Inside China and Outside China tabs, select the regions to block, then click Save.

    The IP blacklist takes effect immediately after you enable it. WAF blocks all requests from blacklisted IP addresses.

Related operations