Would this WAF rule work the way I want it to?
Essentially, I want to block everyone but me (my IP) from accessing
wp-admin
, wp-admin.php
, wp-login
and wp-login.php
.
Would the wildcard below work?data:image/s3,"s3://crabby-images/acd76/acd76fea72ecbcd5d8ef8113feed05d49f97ac04" alt="No description"
11 Replies
Stump... Saved someone the trouble of testing it for me.
Can someone please suggest a better WAF rule? Thanks :)
data:image/s3,"s3://crabby-images/c4925/c49253551b86174b06d799dff34d4ffcb1e9bc7a" alt="No description"
Hostname eq AND
URI Path
is in
AND
IP Source Address is not inAnd then i do OR and repeat that statement for wp-admin?
no it'd be part of the URI Path is in list
like so
Oh I see
Thanks :)
data:image/s3,"s3://crabby-images/e130b/e130b6e100a52a63640f9ee6b239ad93c664c1bb" alt="No description"
missing the .php extensions but you get the point
👍
Path field doesn't include query params so don't have to worry about those
Deployed and it works. Thanks again :)
closing this post
were you able to implement this rule using FREE PLAN?