ip Blocking

Block IP Ranges with CIDR

Block entire IP ranges efficiently using CIDR notation. Perfect for blocking networks, not just individual IPs.

How SecurEcommerce Blocks IP Ranges

CIDR notation support allows blocking entire networks with a single rule

What is CIDR Blocking?

CIDR (Classless Inter-Domain Routing) lets you block ranges of IP addresses with a single rule:

  • Single IP: 192.168.1.100
  • Small range: 192.168.1.0/24 (256 IPs)
  • Large range: 192.168.0.0/16 (65,536 IPs)

Instead of adding thousands of individual IPs, one CIDR rule handles them all.

Understanding CIDR Notation

Format

IP_ADDRESS/PREFIX_LENGTH

Common Prefix Lengths

PrefixIPs CoveredUse Case
/321 IPSingle address
/24256 IPsSmall network
/1665,536 IPsLarge network
/816.7M IPsHuge range

Examples

  • 45.33.32.0/24 - Blocks 45.33.32.0 through 45.33.32.255
  • 103.21.244.0/22 - Blocks 1,024 IPs
  • 192.168.0.0/16 - Blocks entire 192.168.x.x range

Implementation

Add CIDR Block

  1. Open SecurEcommerce
  2. Navigate to Blocking > IP Blocking
  3. Click “Add IP”
  4. Enter CIDR notation (e.g., 192.168.1.0/24)
  5. Add descriptive note
  6. Save

Finding Ranges to Block

From Attack Logs

  1. Identify attacking IPs
  2. Look up their network range
  3. Block the entire range

Using WHOIS

  1. Look up suspicious IP
  2. Find assigned netblock
  3. Convert to CIDR

From Threat Intelligence

  1. Security feeds provide ranges
  2. Known malicious networks
  3. Add as CIDR blocks

When to Use Range Blocking

Good Use Cases

  • Entire networks attacking - Multiple IPs from same source
  • Known bad ASNs - Hosting providers, data centers
  • Corporate blocks - Entire company if abusing
  • Geographic ranges - Supplement country blocking

Use Caution

  • Large ranges may include innocent IPs
  • ISPs serve many customers
  • Verify range ownership first

Finding Network Information

WHOIS Lookup

Search for IP ownership:

  • whois.domaintools.com
  • who.is
  • bgp.he.net

ASN to CIDR

Convert ASN to IP ranges:

  • bgp.he.net/ASXXXXX
  • Lists all prefixes announced

IP Range Calculator

Tools to calculate CIDR:

  • ipaddressguide.com/cidr
  • Calculate subnet masks

Best Practices

Document Everything

For each CIDR block, record:

  • Why it was blocked
  • When it was added
  • Source of intelligence
  • Review date

Start Narrow

  • Begin with /24 ranges
  • Expand only if needed
  • Avoid overly broad blocks

Regular Review

  • Monthly audit of CIDR blocks
  • Remove outdated entries
  • Verify still necessary

Examples of CIDR Blocking

Blocking an Attacker’s Network

Attack from 185.220.101.35:

  1. WHOIS lookup
  2. Find netblock: 185.220.101.0/24
  3. Add CIDR block
  4. Blocks future attacks from that network

Blocking a Hosting Provider Subnet

Bot traffic from DigitalOcean range:

  1. Identify specific subnet
  2. Add 104.236.0.0/16
  3. Blocks that DO range

Blocking a Country’s ISP

Fraud from specific ISP:

  1. Find ISP’s IP ranges
  2. Add multiple CIDR blocks
  3. More precise than country blocking

Combining with Other Rules

CIDR blocking works with:

  • Individual IP blocks
  • Country blocking
  • ISP blocking
  • VPN/Proxy blocking

Rules are evaluated together for comprehensive protection.

Related Security Threats

Start Blocking IP Ranges in Minutes

SecurEcommerce makes it easy to block unwanted traffic from your Shopify store. Install now and configure blocking in just a few clicks.

★★★★★ 5/5 on Shopify 7-day free trial No credit card required