Title: WhiteList
Last modified: August 31, 2016

---

# WhiteList

 *  Resolved [Rik0399](https://wordpress.org/support/users/rik0399/)
 * (@rik0399)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/)
 * Hi,
 * So I tried to block an IP address but, it says this :
 * ‘The IP address ***.216.19.*** is whitelisted and can’t be blocked or it is in
   a range of internal IP addresses that Wordfence does not block. You can remove
   this IP from the whitelist on the Wordfence options page.’
 * Thing is, when looking in ‘options’; nothing in there to show this IP?
 * I did not add this to a whitelist? So How or where do I go to block it?
 * Many Thanks
 * [https://wordpress.org/plugins/wordfence/](https://wordpress.org/plugins/wordfence/)

Viewing 11 replies - 1 through 11 (of 11 total)

 *  [WFBrian](https://wordpress.org/support/users/wfbrian/)
 * (@wfbrian)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7190970)
 * HI,
 * If it is not listed under the whitelist, then it may be a private IP that we 
   don’t block. What numbers do the IP address start with? Possibly 10, 172, or 
   192?
 * Thanks!
    Brian
 *  Thread Starter [Rik0399](https://wordpress.org/support/users/rik0399/)
 * (@rik0399)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7190977)
 * Hi Matt,
 * This > 69.63.188.206
 * Can’t block or anything?
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191018)
 * 69.63.188.206 is Facebook, according to lookup?
 *  Thread Starter [Rik0399](https://wordpress.org/support/users/rik0399/)
 * (@rik0399)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191025)
 * [@mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * It appears so, but it cannot be blocked for some reason?
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191064)
 * In what Wordfence setting are you attempting to block this IP?
 *  Thread Starter [Rik0399](https://wordpress.org/support/users/rik0399/)
 * (@rik0399)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191076)
 * [@mountainguy2](https://wordpress.org/support/users/mountainguy2/),
 * I have tried all ways without success.
 * And the other BIG problem of course is that spammers and hackers using various
   dynamic ip addresses and using sites which I have links on, to attack the site.
 * The issue with that is if you block each event; you end up blocking innocent 
   visitors who fall with the spammers ip range.
 * Regards,
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191079)
 * Rik, if you really want to block a single IP address from your website, just 
   do it with your .htaccess file or your server firewall. You can also put it in
   your blacklist in WordPress/Discussion/Settings if you’re getting pestered by
   a single spammer and don’t want to fiddle with .htaccess and stuff like that.
 * In Wordfence, country blocking can be very effective at reducing spam attempts,
   in my experience. I’m told that in places such as Brazil and India they have 
   what are virtually spam factories, with hundreds and even thousands of people
   paid to just sit there all day and try to spam us. I don’t need traffic from 
   Brazil, so I block, then give access to individuals who request it by contacting
   me on Facebook, using the Wordfence options.
 * I have a high traffic blog website and don’t require registration for comments,
   and only get one or two spam comments a week. I don’t use a specific anti-spam
   plugin. Instead, I use moderation blacklist combined with country blocking (Wordfence
   Premium), other Wordfence settings, and a challenge question the comment author
   has to answer, like “what color is the sky?” to block most bots and human spam
   slaves who sometimes can’t even understand English. I use pretty strict settings
   in Wordfence to block the bot swarm, as well as a honey pot system (hidden link
   to a non-existent file, Wordfence blocks any IP which tries to access.)
 * Interestingly, now that I’ve got the spam bots under control my biggest problem
   is a large number of attack hits on my SFTP and Control Panel logins, things 
   that Wordfence does nothing to help with but I trust will eventually be integrated.
   These are more than ugly comment spam, they are attempts to make a security breach.
 * MTN
 *  Thread Starter [Rik0399](https://wordpress.org/support/users/rik0399/)
 * (@rik0399)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191081)
 * [@mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * Thanks for that, most helpful 😉
 * I’ll try what you suggest and hopefully get it under control.
 * I guess I worry that I may block people who want to visit the site so using Country
   blocker is a problem
 * Again, many thanks for you time in posting 😉
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191088)
 * Indeed, some websites indeed have truly international appeal and country blocking
   would be inappropriate, but most websites in my opinion can do with some country
   blocking, just base it on analyzing where your spam attacks come from and be 
   realistic about where you expect to get site traffic from. Also, you can easily
   tweak the block messages and add a suggestion that users contact you on Facebook
   if they get blocked and want access. You can then give them the secret WF URL
   that drops a cookie on their computer and gives them access. It actually can 
   add a personal touch that can gain you readers/fans.
 * Some folks don’t understand that we pay money for bandwidth, and will accuse 
   you of things like xenophobia and such when they get country blocked. Just tell
   them to go ask the hackers in their country to stop attacking us.
 * Plus, once you get a look at your server you’ll see a whole other level of attacks
   that Wordfence has nothing to do with. Again, country blocking can be a good 
   way of limiting some of this.
 * Currently, I’ve heard that upwards of 30% of web traffic is criminal or otherwise
   useless bot traffic, and that traffic uses the equivalent of 1/2 the electrical
   output of the UK. Greenhouse gas, anyone?
 * MTN
 *  Plugin Author [WFMattR](https://wordpress.org/support/users/wfmattr/)
 * (@wfmattr)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191125)
 * Hi,
 * Catching up here — for the original issue above, known Facebook IPs were recently
   added to the internal whitelist (the change had a small mention in our [changelog here](https://wordpress.org/plugins/wordfence/changelog/)),
   to help prevent unintentional blocking on sites that have set strict rules, especially
   since Facebook is crawling from multiple countries now.
 * [@mountainguy2](https://wordpress.org/support/users/mountainguy2/): Thanks again
   for helping out! By the way, for attacks on SFTP/SSH, installing “fail2ban” might
   be helpful, if you’re not already using it. It monitors logs for login failures
   and uses iptables to block bad IPs from various services (usually not HTTP, without
   customization though).
 * -Matt R
 *  [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * (@mountainguy2)
 * [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191126)
 * Thanks Matt, I’m gradually getting better at using my server firewall that the
   hosting company standardizes with, CSF. I set it up to ban by IP number after
   just 2 or 3 login failures in an hour. With super secure passwords on FTP and
   SSH that can’t be guessed, I’m thinking this is working pretty well. It actually
   acts as a honey pot. I also set up a bunch of full country blocks on the FTP/
   SFTP ports, those are incredibly effective in preventing criminals from trying
   to access FTP.
 * I know this is a bit off topic for this thread, but to swing back on topic, I’d
   suggest two things:
    1. Once anyone gets serious about website security and using
   Wordfence for IP blocking, it’s a good idea to check with server hosting company
   to see what kind of firewall they’re using and if you can configure it yourself.
   2. As a feature request… it seems so 1980s to be spending tons of time with Wordfence,
   only to find it does nothing to help with attacks on server login, and instead
   the poor beleaguered website owner has to learn yet another application. So, 
   someday, will we have one place to go for all firewall/security settings? Wordfence-
   Ultimate?

Viewing 11 replies - 1 through 11 (of 11 total)

The topic ‘WhiteList’ is closed to new replies.

 * ![](https://ps.w.org/wordfence/assets/icon.svg?rev=2070865)
 * [Wordfence Security - Firewall, Malware Scan, and Login Security](https://wordpress.org/plugins/wordfence/)
 * [Frequently Asked Questions](https://wordpress.org/plugins/wordfence/#faq)
 * [Support Threads](https://wordpress.org/support/plugin/wordfence/)
 * [Active Topics](https://wordpress.org/support/plugin/wordfence/active/)
 * [Unresolved Topics](https://wordpress.org/support/plugin/wordfence/unresolved/)
 * [Reviews](https://wordpress.org/support/plugin/wordfence/reviews/)

 * 11 replies
 * 4 participants
 * Last reply from: [mountainguy2](https://wordpress.org/support/users/mountainguy2/)
 * Last activity: [10 years, 1 month ago](https://wordpress.org/support/topic/whitelist-9/#post-7191126)
 * Status: resolved