MODULES / Allowlist / Blocklist

Exceptions and blocks, from one screen

Allowlist / Blocklist

Allowlist your trusted IPs to prevent false-positive alerts. Add known attackers to a permanent blocklist.

  • EXCEPTION
  • BLOCK
  • AUDIT TRAIL

[ PURPOSE & VALUE ]

What does Allowlist / Blocklist do?

One of the most common problems in security systems is your own developers' or authorized penetration-testing teams' activity being mistaken for an attack and blocked. This disrupts workflows and creates unnecessary workload for SOC teams. The Allowlist/Blocklist module lets you manage these exceptions and permanent blocks securely from a single panel.

[ FEATURES ]

What Allowlist / Blocklist delivers

Allowlist Exceptions

Suspicious web requests or scans from IPs added here never trigger an alert or email from the correlation engine.

Logged Justifications

Transparent tracking of which IP was added by which administrator and for what reason.

Permanent Blocklist

Completely cuts off known malicious bot IPs or attacker addresses from accessing your websites and services at the server level.

[ HOW IT WORKS ]

Live in three steps

Define

An exception or block entry is created per IP/user.

Approve

The change is written to the audit trail.

Apply

The rule is instantly propagated to the relevant modules.

[ RELATED MODULES ]

Works together with Allowlist / Blocklist

[ FAQ ]

Frequently asked questions about Allowlist / Blocklist

How do I stop our pentest team's scans from being blocked by mistake?

Add your team's IP addresses to the allowlist — suspicious requests from those IPs will never trigger the correlation engine.

Is a blocklisted IP's access cut off completely?

Yes — permanently blocklisted IPs are denied access to all your websites and services at the server level.

See Allowlist / Blocklist live

Headquarters: Ankara · iletisim@nextpacketcapture.com