Get a free website with any plan

See how
TROUBLESHOOTING

When the firewall blocks a legitimate request

Last updated

IN SHORT

If a legitimate visitor or service is blocked on Flashcloud hosting, whitelist the specific IP address in Imunify360 through cPanel. Never disable firewall protection site-wide. Imunify360 flags patterns like high request rates or webhooks that mimic attacks. Whitelisting the exact IP bypasses future rule checks for that source while keeping the server secure.

If a legitimate visitor, script, or API call is getting blocked, the fix is almost always to whitelist the specific IP address in the web application firewall, not to disable protection site-wide. On Flashcloud hosting, that firewall is Imunify360, reachable from cPanel. Find the block, confirm it's actually the firewall (and not something else, like DNS or a redirect loop), then allow the exact IP that needs through.

Firewalls work on pattern matching: request rate, suspicious paths, known bad signatures, geographic anomalies. Legitimate traffic sometimes trips those patterns too. A monitoring service hitting your site every minute, a payment gateway calling back to a webhook, or an office network sharing one public IP with dozens of employees can all look suspicious to a firewall rule. None of that means the firewall is broken. It means one rule was too aggressive for one specific source, and the fix is narrow.

Confirm it's actually the firewall

Before you touch any firewall setting, rule out the other usual suspects. A blocked request and a broken request look similar from the outside.

  • If the page won't load at all and shows a DNS error rather than a "forbidden" or "access denied" message, that's not a firewall problem. See fixing DNS_PROBE_FINISHED_NXDOMAIN.
  • If you're getting a gateway error instead of a block page, the request may be timing out upstream rather than being rejected. See fixing 502 and 504 gateway errors.
  • A genuine firewall block usually shows a distinct block page or returns an HTTP 403. If you're not sure what the visitor actually saw, ask them to send a screenshot or, better, a HAR file capturing the exact response. See generating a HAR file for support.

Find the block in Imunify360

Log in to your hosting account at portal.flashcloud.com, open cPanel for the domain, and go to the Security section to open Imunify360. If you are locked out by the firewall, use the Unblock My IP tile on the service details page in the portal.

If you don't know the IP offhand, most third-party services publish the IP ranges they send requests from, check the service's own documentation. If it appears in the block list, you'll see why it was flagged and when.

Whitelist the specific IP

To whitelist external webhook or API IPs that cannot be handled via self-service tools, contact support. Whitelisting tells the firewall to stop evaluating that address against its rules going forward, rather than clearing the current block.

Whitelist the narrowest thing that solves the problem:

  • For a single visitor or office, whitelist that one IP address.
  • For a service that calls your site from a published range of addresses, such as a payment processor's webhook servers, whitelist the documented range, not a broad guess.
  • Avoid whitelisting large blocks or entire subnets you don't recognize. That defeats the purpose of having a firewall at all.

If the same IP keeps getting blocked after whitelisting, double check you whitelisted the address the request is actually coming from. Requests can pass through load balancers, VPNs, or proxies on the sending side, so the IP hitting your firewall isn't always the one you expect.

When it's your own site triggering the block

Sometimes what looks like a firewall problem is actually your own application making requests that resemble an attack pattern: a script hammering an API endpoint in a tight loop, a poorly configured cron job retrying too fast, or a plugin making unusually frequent outbound calls. If unblocking the IP doesn't hold, or the same source keeps reappearing in the block list, check your own logs before assuming the firewall is wrong. Turning on logging will show you the request pattern that preceded the block, see enabling error logging for where those logs live.

If you're behind Cloudflare

If the domain is proxied through Cloudflare, a block can also originate at Cloudflare's edge rather than on the server. Check the Cloudflare CDN page in the portal for that domain's security level and any Under Attack mode setting, and confirm proxy status before assuming Imunify360 is the source. A Cloudflare-branded block page means Cloudflare stopped the request before it reached your hosting account at all, in that case the fix happens in the Cloudflare settings, not in cPanel.

When to contact support

If you can't identify why an IP was flagged, if whitelisting doesn't stop repeat blocks, or if you suspect the block is masking a different underlying issue, open a support ticket from the portal. Include the IP address, the approximate time of the blocked request, and, if you have one, a HAR file. Support can investigate further and tell you whether a broader rule needs adjusting rather than a one-off whitelist.

Common questions

How do I unblock my own IP if I am locked out?

Use the Unblock My IP tile on the service details page in portal.flashcloud.com. This option restores access directly if the server firewall blocks your connection.

Why does an IP keep getting blocked after whitelisting?

You likely whitelisted the wrong IP address. Traffic frequently routes through proxies, VPNs, or load balancers, meaning the IP reaching the firewall is not the one you expected.

Did Cloudflare or the server firewall block the request?

Check the block screen for Cloudflare branding. A Cloudflare-branded page means the block occurred at the edge before reaching your server, which requires updating Cloudflare settings rather than cPanel.

How do I whitelist a payment gateway webhook?

Contact support with the published IP range from the service documentation. Whitelisting external webhook or API addresses that cannot be configured through self-service tools requires assistance from support.

CAN'T FIND IT?

Real humans answer fast.

Hosting with us? Open a ticket and a real person replies - no scripts, no upsells. Still choosing a host? The same team is included with every plan, from day one.