If a legitimate visitor, script, or API call is getting blocked, the fix is almost always to whitelist the specific IP address in the web application firewall, not to disable protection site-wide. On Flashcloud hosting, that firewall is Imunify360, reachable from cPanel. Find the block, confirm it's actually the firewall (and not something else, like DNS or a redirect loop), then allow the exact IP that needs through.
Firewalls work on pattern matching: request rate, suspicious paths, known bad signatures, geographic anomalies. Legitimate traffic sometimes trips those patterns too. A monitoring service hitting your site every minute, a payment gateway calling back to a webhook, or an office network sharing one public IP with dozens of employees can all look suspicious to a firewall rule. None of that means the firewall is broken. It means one rule was too aggressive for one specific source, and the fix is narrow.
Confirm it's actually the firewall
Before you touch any firewall setting, rule out the other usual suspects. A blocked request and a broken request look similar from the outside.
- If the page won't load at all and shows a DNS error rather than a "forbidden" or "access denied" message, that's not a firewall problem. See fixing DNS_PROBE_FINISHED_NXDOMAIN.
- If you're getting a gateway error instead of a block page, the request may be timing out upstream rather than being rejected. See fixing 502 and 504 gateway errors.
- A genuine firewall block usually shows a distinct block page or returns an HTTP 403. If you're not sure what the visitor actually saw, ask them to send a screenshot or, better, a HAR file capturing the exact response. See generating a HAR file for support.
Find the block in Imunify360
Log in to your hosting account at portal.flashcloud.com, open cPanel for the domain, and go to the Security section to open Imunify360. If you are locked out by the firewall, use the Unblock My IP tile on the service details page in the portal.
If you don't know the IP offhand, most third-party services publish the IP ranges they send requests from, check the service's own documentation. If it appears in the block list, you'll see why it was flagged and when.
Whitelist the specific IP
To whitelist external webhook or API IPs that cannot be handled via self-service tools, contact support. Whitelisting tells the firewall to stop evaluating that address against its rules going forward, rather than clearing the current block.
Whitelist the narrowest thing that solves the problem:
- For a single visitor or office, whitelist that one IP address.
- For a service that calls your site from a published range of addresses, such as a payment processor's webhook servers, whitelist the documented range, not a broad guess.
- Avoid whitelisting large blocks or entire subnets you don't recognize. That defeats the purpose of having a firewall at all.
If the same IP keeps getting blocked after whitelisting, double check you whitelisted the address the request is actually coming from. Requests can pass through load balancers, VPNs, or proxies on the sending side, so the IP hitting your firewall isn't always the one you expect.
When it's your own site triggering the block
Sometimes what looks like a firewall problem is actually your own application making requests that resemble an attack pattern: a script hammering an API endpoint in a tight loop, a poorly configured cron job retrying too fast, or a plugin making unusually frequent outbound calls. If unblocking the IP doesn't hold, or the same source keeps reappearing in the block list, check your own logs before assuming the firewall is wrong. Turning on logging will show you the request pattern that preceded the block, see enabling error logging for where those logs live.
If you're behind Cloudflare
If the domain is proxied through Cloudflare, a block can also originate at Cloudflare's edge rather than on the server. Check the Cloudflare CDN page in the portal for that domain's security level and any Under Attack mode setting, and confirm proxy status before assuming Imunify360 is the source. A Cloudflare-branded block page means Cloudflare stopped the request before it reached your hosting account at all, in that case the fix happens in the Cloudflare settings, not in cPanel.
When to contact support
If you can't identify why an IP was flagged, if whitelisting doesn't stop repeat blocks, or if you suspect the block is masking a different underlying issue, open a support ticket from the portal. Include the IP address, the approximate time of the blocked request, and, if you have one, a HAR file. Support can investigate further and tell you whether a broader rule needs adjusting rather than a one-off whitelist.