Aegisify company logo
Aegisify WAF Block & White Listing Algo2026-08-12T03:08:27+00:00
Aegisify WAF — Block / White List

Control Who Gets Blocked Without Turning Trust Into a Blind Spot

Aegisify WAF gives WordPress administrators one place to review active temporary bans, release sources, promote confirmed abuse into permanent IPv4, IPv6, or CIDR blocks, import validated block lists, and maintain narrow allowances for trusted routes, services, origins, and integrations.

Blocking is easy. Blocking the right thing—and undoing the wrong decision safely—is the operational challenge.
Aegisify separates temporary containment, permanent denial, trusted-service coordination, and short-lived compatibility exceptions so administrators can tighten security without replacing evidence with guesswork.

1Reviewsource + evidence
2Controlrelease or block
3Verifytraffic still works

Operational Workflow

Move From a WAF Decision to a Controlled Source Policy

Open each stage to see how Aegisify WAF 1.20.13 separates investigation, containment, long-term blocking, and compatibility handling.

Click a stage to expand

01Observelogs + block state
Review the latest WAF event, source address, action, route, reason, status, and available country context before deciding whether the source is malicious, misconfigured, or legitimate.
02Containtemporary ban
Temporary bans may come from administrator action or supported defense layers such as authentication defense, adaptive controls, DDoS cooldowns, and protected Aegisify transport logic. They remain releasable and expire automatically.
03Releaserestore access
If the evidence shows a false positive or a trusted integration was affected, release the active temporary block immediately instead of disabling an entire WAF module.
04Escalatepermanent address
Confirmed abusive IPv4, IPv6, or CIDR sources can be promoted or added to the permanent list. Permanent entries are stored separately and do not auto-expire.
05Allow Narrowlyverified requirement
Use route, origin, IP/CIDR, plugin-template, or short-lived source-route-method allowances only when the business requirement is known. A whitelist is an exception to selected controls, not authentication.
06Rechecksecurity + availability
After changing a block or allowance, confirm the intended workflow works and review new WAF evidence to make sure the exception did not remove more protection than necessary.
Temporary Blocks

Contain Abuse Without Making Every Decision Permanent

Temporary bans create a recoverable response path for suspicious or excessive traffic while an administrator determines whether stronger action is justified.

Aegisify WAF surfaces temporary blocks separately from permanent entries and can synchronize active bans generated by administrator action, adaptive defense, credential-stuffing protection, DDoS cooldowns, and protected Aegisify transport defenses.

Administrators can add a temporary address for one hour, 24 hours, seven days, or 30 days. Entries retain source/scope, reason, and expiration context. Remove / Release restores access immediately, while confirmed abuse can be promoted into the permanent list.

Security posture: temporary containment reduces pressure quickly while preserving reversibility. That is safer than immediately turning an uncertain event into a permanent network-wide denial.
Permanent Blocking

Use Permanent IPv4, IPv6, and CIDR Blocks for Confirmed Sources

Long-lived denial belongs in a separate policy with stronger validation and explicit administrator ownership.

Address Coverage

IPv4, IPv6 & CIDR

The permanent list accepts validated IPv4, IPv6, and CIDR values, letting teams deny one source or a defined network without broad geographic blocking.

Lifecycle

No Automatic Expiration

Permanent entries are intentionally different from temporary bans. They remain in force until an administrator removes them, so the reason and scope should be reviewed before promotion.

Bulk Operations

Validated Imports

Aegisify can import permanent addresses and CIDR ranges from a trusted source. Inputs are parsed, validated, deduplicated, capacity-checked, and reviewed for the possibility of blocking the administrator’s current source address.

Do not turn external lists into automatic truth. Reputation feeds and shared block lists can be stale or overly broad. Import only a source you trust, review the resulting scope, and confirm that payment services, remote administrators, monitoring systems, APIs, and business partners are not covered by an imported CIDR range.
Evidence Before Escalation

Review Blocked Sources With Operational Context

Aegisify WAF keeps retained block evidence useful by showing more than the address alone.

01 — Latest Activity

Source, Route, Action, Reason

The Block List can surface unique sources retained in WAF activity with their latest blocking event, route, action, status, source module, last-seen time, and reason. That context helps distinguish an attack signature from a rate-control event or compatibility problem.

02 — Country Context

Useful Signal, Not Identity

Country information may come from the event itself or the configured local Geo/ASN provider. IP geolocation is approximate, so geography should support investigation rather than serve as proof of attacker identity or intent.

03 — Active State

Temporary vs. Permanent

Administrators can tell whether the source currently has a temporary ban, already appears in the permanent list, or is simply represented in retained evidence. This prevents an old log event from being mistaken for a currently active block.

04 — Recovery

Release Before Disabling Protection

If one customer, webhook, crawler, or administrator was blocked incorrectly, remove the narrow source decision first. Broadly disabling WAF, API, bot, or DDoS protection should not be the first compatibility response.

White List

Coordinate Trusted Traffic Without Removing Its Own Authentication

Aegisify’s White List is designed for narrowly defined operational compatibility, including trusted Aegisify services and reviewed WordPress integrations.

The effective White List combines reviewed manual entries with supported plugin templates. It manages REST routes, front paths, trusted origins, IP/CIDR entries, and service-port inventory. Installed Aegisify components can contribute known templates, while plugin scanning can identify REST namespaces for administrator review.

Applicable entries synchronize into REST, CORS, DDoS source, and DDoS endpoint allowances. Port values remain inventory data because a WordPress/PHP WAF does not open or close network firewall ports.

A whitelist is not authentication. Allowing a route, origin, or source through selected WAF controls does not prove that the caller is authorized. Signed Aegisify services continue to validate their own requests, and third-party integrations should continue using nonces, signatures, API credentials, OAuth, mutual TLS, or another appropriate authorization mechanism.
Compatibility Without Broad Bypass

Use the Smallest Exception That Solves the Real Problem

Aegisify 1.20.13 also supports narrow temporary allow overrides tied to a specific source, route, and HTTP method.

1Bind the SourceDo not allow every visitor when one known integration source is affected.
2Bind the RouteKeep the exception on the endpoint that actually needs compatibility handling.
3Bind the MethodA GET requirement should not silently authorize unrelated POST, PUT, PATCH, or DELETE traffic.
4Expire ItTemporary overrides are time-bound, creating a natural point to retest and remove the exception.

Put the Controls to Work

Start With Evidence, Then Tighten the Smallest Necessary Scope

Use Aegisify WAF to manage abusive sources and trusted integrations without treating every block as permanent or every compatibility problem as a reason to disable protection.

Block / White List FAQ

Common Operational Questions

Do temporary bans expire automatically?

Yes. Temporary blocks have an expiration and can also be released immediately. Permanent entries are stored separately and remain until an administrator removes them.

Can I permanently block IPv6 or a network range?

Yes. The permanent block manager validates IPv4, IPv6, and CIDR values so a single address or defined network range can be denied.

Does whitelisting an API route authenticate the caller?

No. A whitelist changes selected WAF handling. The integration still needs its own authentication and authorization controls.

Should I trust country information as proof of an attacker?

No. IP geolocation is approximate. Use country context as one investigation signal and prefer route, rule, behavior, and source evidence when making a blocking decision.

Control Without Guesswork

Make Blocking Reversible, Permanent Denial Deliberate, and Trust Narrow

Aegisify WAF turns source control into an operational workflow: review the evidence, contain abuse, release mistakes, escalate confirmed sources, and preserve legitimate integrations with the smallest effective allowance.