# Firewall

IP blocking is managed at the **server level** by your hosting provider; there is no per-account firewall. The panel's Firewall page says so and does not offer a block form — the server has one rule set that affects every site on it, so a tenant cannot add, remove or even list blocks. If an address should be blocked (a comment spammer, a credential-stuffing source) or unblocked (your own office after a mistaken ban), contact support.

Automatic protection still applies to your sites: Fail2Ban acts on abusive addresses without any action on your side. Connection rate limits are server rules your hosting provider sets up; none apply unless they have added them.

### Web Application Firewall (resellers)

If your account is a reseller, each sub-account's page carries a **Web Application Firewall**
card with a ModSecurity switch. Turning it off stops the OWASP rule set from inspecting requests
to that sub-account's sites — useful when a rule keeps blocking a legitimate application, and
worth turning back on once the application is fixed.

The card is always shown; its switch appears only when your reseller plan allows firewall
management. If it does not, the card says so rather than showing the firewall as off.

**What your reseller plan withholds is not offered.** When your plan does not include a
capability — databases, e-mail, FTP, DNS, SSL, the file manager, cron jobs, logs — its entry is
left out of the menu, and the **Remote** tab of Backups is shown only when the plan allows remote
destinations. The same applies while you are signed in to one of your sub-accounts.

---
