Search...
Menu

IP Blacklist

The IP blacklist is used to restrict access from specific IP addresses. Once an IP address is added to the blacklist, any registration or login requests originating from that IP will be automatically rejected by the system. This feature effectively mitigates malicious activities such as brute-force attacks and bulk registrations, enhancing application security.

Path: Log in to the RootAuth console → Navigate to the target application → Click Configuration in the top navigation bar → Select Security Settings – Risk Policies → IP Blacklist

 

1. Feature Overview

  • After adding specific IP addresses to the blacklist, registration or login requests from these IPs will be automatically rejected by the system.

  • Supports batch addition of multiple IP addresses, with each IP managed independently, allowing for flexible control.

  • All configurations apply only to the current application and are isolated from other applications, ensuring no interference.

 

2. Operation Guide

2.1 Viewing the Blacklist

The blacklist page displays all added IP records in a table format, with 10 entries per page by default.

Field Description Example
IP The restricted IP address 183.6.116.162
Restriction Type Fixed as "Block Registration/Login" Block Registration/Login
Added Time The time the record was added, in the format YYYY-MM-DD HH:mm:ss, automatically converted to your browser's time zone 2026-02-26 17:30:27
Actions Click "Delete" to remove the IP from the blacklist [Delete]

List Operations:

  • Search: The search box in the upper-left corner of the list supports fuzzy searching by IP address, allowing you to quickly locate target records.

  • Refresh: The list automatically refreshes after adding or deleting IPs.

 

2.2 Adding an IP to the Blacklist

Click the "+ Add IP" button in the upper-right corner of the list to open the addition window.

Field Descriptions:

Field Required Description
IP Yes Supports a single IP (e.g., 123.45.67.89) or multiple IPs. For multiple IPs, separate them with commas (e.g., 123.45.67.89, 203.0.113.5). A maximum of 100 IPs can be added at once.
Restriction Type Yes Fixed as "Block Registration/Login" and cannot be changed.

Important Notes During Addition:

  • Format Validation: The system will check the format of each IP in real time as you type. If the format is incorrect, you will be immediately prompted to correct it.

  • Duplicate Handling: Upon submission, the system automatically filters out IPs that already exist in the blacklist and only adds new ones. No additional action is required from you.

  • Addition Result: Regardless of how many IPs you add at once, each IP will appear as a separate record in the list for convenient individual management.

Steps:

  1. Enter the IP address(es) you want to restrict in the input field.

  2. Click "Confirm" to save.

  3. The window closes, and the list automatically refreshes. The newly added IP(s) take effect immediately.

Tip: If you want to temporarily test whether a specific IP is blocked, you can add it and then delete it—it's a simple process.

 

2.3 Removing an IP from the Blacklist

When an IP no longer needs to be restricted, you can remove it from the blacklist:

  1. Locate the IP you want to remove in the list.

  2. Click the "Delete" button in the corresponding row.

  3. In the confirmation dialog that appears, click "Confirm" to complete the removal.

 

3. Usage Recommendations and Verification

3.1 When to Use the IP Blacklist?

  • When you notice a specific IP repeatedly failing login attempts (suspected brute-force attack).

  • When you detect bulk registration activity originating from certain IP ranges.

  • When you need to temporarily block access from a specific IP.

3.2 How to Verify That the Configuration Is Effective?

You can quickly test it as follows:

  1. Add your current device's public IP address to the blacklist.

  2. Attempt to access the application's login or registration page.

  3. You will find that the login/registration request is rejected, confirming that the blacklist is active.

Note: Remember to remove your IP from the blacklist after testing to avoid affecting normal usage.

 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
Previous
Risk Policies
Next
User Management
Last modified: 2026-03-11Powered by