Use Tools → Security to see which IP addresses are temporarily locked out, review requests that were blocked or limited, and manage permanent IP rules. Start by finding the reason for a restriction before changing access.
Check the overview
Open Overview for the current lockouts and a summary of recent protection activity.
- Locked out now counts distinct IP addresses. One address can have more than one type of lockout.
- Blocked or limited counts restricted requests in the reporting window, not people currently locked out.
- Requests evaluated counts requests checked during that window. It is not a visitor count.
Temporary lockouts expire automatically. In Active lockouts, check the IP address, reason, hits, and Expires time. Hover over a time to see its exact date and time. Some entries also show the most frequently requested routes.
An IP address can be shared by several people on an office network, a mobile network, or a VPN. Review the activity before treating it as one person's behavior.
Understand the lockout reason
Rate limit. Too many requests arrived from an address. Look for a request loop, excessive retries, or a legitimate service sending requests too quickly.
Failed sign-ins. Repeated unsuccessful sign-in attempts triggered protection. Confirm that the affected person is using the correct account and help them reset their password if needed.
Scanner trap. Requests reached paths commonly probed by automated scanners. Review the requested paths and identify the source before lifting the lockout.
Clearing a lockout removes that selected restriction for the IP address. It does not remove a permanent block-list entry, change a password, or guarantee that every other sign-in or traffic check will allow the next request.
Review blocked and limited requests
Select Review activity or open Activity to see Site protection.
- Check the reporting window and whether the report is Live or shows an older Last updated time.
- Under Traffic shown, keep Public traffic for visitor-facing requests. Choose All traffic when investigating an admin request.
- Review Actions taken, Reasons, Route types, and Top paths where shown. Use the reason and path together to understand what was restricted.
- In Recent requests, use Needs review to focus on requests that drew extra attention, or All requests for the available sample. Select Show all to expand more of the loaded requests.
The Overview totals and Activity tab badge include admin traffic. The Activity report defaults to public traffic, so its visible counts can be lower until you choose All traffic.
Client pressure means some clients triggered extra protection; it does not by itself mean requests were blocked. Likewise, a message that site-wide protection reached a higher mode describes the reporting window, not necessarily the site's state at this moment.
Recent requests are a sample, not a complete traffic log. The totals cover the reporting window even when the request list shows fewer rows. Older activity can also fall outside that window.
Help a legitimate visitor regain access
- Ask for the approximate time, page or action, and exact error. If an IP address is needed to identify the restriction, collect it privately.
- Match the report to Active lockouts and Activity. Confirm the reason and check whether the address is also on the Block list under IP rules.
- Address the cause first—for example, stop repeated requests or use password reset instead of continuing to guess a password.
- If the temporary lockout is no longer needed, select Clear on that specific row. You can also let it expire naturally.
- Ask the visitor to try once more. If the restriction returns, investigate the new activity before clearing it again.
If the same address has multiple lockouts, review each reason separately. A successful Clear applies to the selected lockout, not every row for that address.
Manage permanent IP rules
Open IP rules to review the two lists. Rules remain until you remove them.
Whitelist skips the general request rate limit for an IP. Sign-in lockouts, scanner-trap protection, and other security checks still apply. Use it for a verified office, monitoring service, or partner that needs to send many legitimate requests.
Block list refuses requests from an IP, including admin requests. Use it for a confirmed source you want to keep blocked after a temporary lockout would expire.
To add a rule, enter an individual IPv4 or IPv6 address in the appropriate list and select Add to whitelist or Add to block list. You can paste several addresses separated by commas or spaces. Enter addresses only, without a website URL, port, or network range.
Changes save immediately. Use Remove beside an address to delete its rule. The success notification offers Undo if you made a mistake.
An address cannot appear on both lists; remove it from the other list first. Each list supports up to 500 addresses. Cedros rejects attempts to block the address you are currently connected from, because doing so would lock you out of the admin.
The action menu beside a lockout also offers Add to block list. Add to whitelist appears only for rate-limit lockouts. These actions create permanent rules, so use Clear when you only intend to lift a temporary lockout.
Resolve missing data or disabled controls
I cannot open Security or change a rule. Ask your administrator to check your feature access. Viewing security information and changing security settings require the appropriate permissions.
Clear or rule changes are disabled after a loading error. Select Retry loading security. Cedros requires a successful current load before allowing the affected changes. An unavailable count or a dash does not mean there are no lockouts.
Lockout data is unavailable, but IP rules still work. Temporary-lockout information and permanent rules can have different availability. Retry loading security and report the error to your site administrator. Only change a permanent rule when you have independently confirmed it is needed.
Activity shows an old update time. Read the refresh error and retry. Previously loaded activity is not a current report while refresh is failing.
An address will not save. Check the inline error for an invalid address, duplicate, conflict with the other list, list limit, or an attempt to block your current connection. Correct the entry and try again.
Someone is still blocked after Clear or Remove. Recheck other lockout rows, the block list, and recent activity. A new lockout, separate account protection, or another security check may still apply. Give your administrator the time, affected action, and error so they can investigate.