IP Query
The IP query function can query the basic information of the specified IP, as well as the request statistics information of the IP accessing WAF during the specified period.
Function Instructions
The function is divided into four parts as shown in the figure below:
- Query Conditions (①, ②)
- IP Information (③, ④, ⑤)
- IP Operation (⑥)
- IP Access Trend (⑦)
Query Conditions
At option ①, select the time range, support the last 1 hour, 24 hours and custom time (within 3 days) as time query conditions, at option ②, enter a single IP, click “Query” to query the basic information and the request statistics information of the IP accessing the current domain during the specified period. If you want to query without distinguishing the domain name, please check “Global Search”. Checking this item can query the request statistics information of the IP access to all domain names.
IP Information
The IP information part displays the basic information of the IP (③), the current status of the IP (④), and the behavior overview of the IP (⑤).
The basic information of the IP includes the attribution, location information, and operator information.
The current state of IP explains whether this IP can access the current domain name normally, indicates whether the IP is blocked by a blacklist or CC rules or is allowed by a whitelist.
The behavior overview of IP counts how many requests have been initiated by the IP during the queried period, how many attacks, and how many times it has been intercepted.
IP Operation
The IP operation part (⑥) can give appropriate operation buttons according to the current status and behavior overview of the IP.
If the IP is blocked by CC rules, the IP can be unbanned; if there is any attack behavior, it can be added to the blacklist; if you need to allow access requests, it can be added to the whitelist; The operation of the queried IP is quick and convenient.
IP Access Trend
The IP access trend (⑦) consists of two parts, which are IP response code requests and IP attack classification requests.
The first part “IP Response Code Requests” counts the response status code information of the queried IP during a specific period, the chart can understand the specific request situation of the IP; the second part “IP Attack Classification Requests” is the statistical information of the attacked requests included in the IP’s access, by chart can intuitively reflect the attack method and trend of the IP. Checking the legend above the chart can accurately select the desired trend information.