Defender blocking all IPS

I need help. Defender is blocking all IPS.

  • Dimitris
    • Support Star

    Hello there Marijn van Verseveld,

    hope you're doing good today! :slight_smile:

    It seems that you were experiencing some issues with our live chat page (?) so I don't have more info on this.

    Is this still happening? And if so, for which domain?
    I've already marked this thread as private so you can freely share any info.

    In order to whitelist an IP, you can use a little MU plugin, like in a new file in /wp-content/mu-plugins/defender-whitelist.php (simply create the /mu-plugins/ folder, if it doesn't exist) and insert the exact snippet in there:

    <?php
    add_filter( 'ip_lockout_default_whitelist_ip', function ( $ips ) {
        $ip    = 'YOUR IP HERE';
        $ips[] = $ip;
    
        return $ips;
    } );

    Looking forward for your feedback!
    Warm regards,
    Dimitris

  • Marijn van Verseveld
    • The Incredible Code Injector

    Hi There,

    Yes i wasn't able to connect with you guys via live chat. Thanks for following up.

    For some reason the domain; https://deraadgevers.nl/ was completely blocked. No one could reach the site.

    Only i could reach the site in my chrome browser. But when trying to reach the site from an incognito tab i'd get the same error as everyone else from Defender; the admin has blocked ......

    Nothing seemed to help, disabling the plugin. Eventually i completely deleted the plugin and reinstalled it. And that seems to have done the trick.

    I have no clue how this happened, no one changed anything on the back-end. And this really can't happen again. This is a huge customer of mine. And they were pretty mad their site wasn't reachable for probably 30 minutes or so.

  • Dimitris
    • Support Star

    Hello Marijn van Verseveld,

    hope you're doing good and I'm really sorry for the frustration here.

    This seems pretty strange case, did you have access to wp-admin area at that time? Or only in frontend pages?

    In case you still have access in such cases, you can check Audit Logging or/and File Scanning as they could extract some additional info on this, apart from the actual IP Lockouts admin pages, where you should be able to see the reported IPs and the reason of the lockout, as well as deactivating lockouts altogether.

    If wp-admin access isn't available, then using FTP and deleting the plugin folder should do the trick.

    Please do come back to us in case this is happening again, we'll investigate further and try to narrow this down! :slight_smile:

    Warm regards,
    Dimitris

  • Marijn van Verseveld
    • The Incredible Code Injector

    Hi there,

    Too bad, i am back again. The same thing happened. All the traffic got blocked again a few minutes ago and again… my customer had to tell me this was happening.

    I can still reach the backend of the website, but in incognito i get blocked too.

    So i deleted the plugin via FTP, then installed it again. But is seems to solve itself after 5 minutes (defender is set to 300sec…)

    Could you guys please help me, and help me look for the problem since this is a big issue, i need to keep this customer satisfied.

    Thanks for helping.

    Marijn

  • Marijn van Verseveld
    • The Incredible Code Injector

    Hi there,

    I've granted access. I would like to hear from you.

    The issue was noticed: 29 september around 14:05. At 14:09 the website was reachable again, after deleting Defender via FTP. But without defender installed or after reinstalling defender the lockdown would stay in place. As said untill 14:09.

    Let me know if you need anything from me!

  • Hoang Ngo
    • Code Slayer

    Marijn van Verseveld,

    I hope you are well today.

    I've checked your site, only 22 lockouts in last 30 days, so I think this might be from your caching plugin. When Defender block an IP, it showing the page with Cache-Control: private in headers and the HTTP status 403, which should not be cached. However, some caching plugin ignore that. I will try to replicate that on my end and see if we have any workaround for this situation.

    Best regards,
    Hoang

Thank NAME, for their help.

Let NAME know exactly why they deserved these points.

Gift a custom amount of points.