Block malicious traffic for Adobe Commerce on Fastly level
This article explains how to block unwanted traffic to your store, not only in response to malicious threats, but also as a method of geographic filtering.
Adobe Commerce on cloud infrastructure (and Fastly CDN) provides tools to manage traffic to your store in response to malicious threats like DDoS attacks. Additionally, it allows you to block requests from specific countries or regions, even if no malicious intent is detected, to comply with business policies, regulatory requirements, or other operational needs.
Affected products and versions:
- Adobe Commerce on cloud infrastructure 2.3.x
In this article we assume that you already have the malicious IPs and/or their country and user agents. Adobe Commerce on cloud infrastructure users would typically get this information from Adobe Commerce support. The following sections provide steps for blocking traffic based on this information. All the changes should be done in the Production environment.
Get access to Admin Panel
If your website is overloaded by DDoS, you might not be able to log in to your Commerce Admin (and perform all the steps described further in this article).
To get access to the Admin, put your website into maintenance mode as described in Enable or disable maintenance mode and whitelist your IP address. Disable the maintenance mode after this is done.
Block traffic by IP
For the Adobe Commerce on cloud infrastructure store, the most effective way to block traffic by specific IP addresses and subnets is adding an ACL for Fastly in the Commerce Admin. Following are the steps with links to more detailed instructions:
- In the Commerce Admin, navigate to Stores > Configuration > Advanced > System > Full Page Cache > Fastly Configuration.
- Create a new ACL with a list of IP addresses or subnets you’re going to block.
- Add it to the ACL list and block as described in the Blocking guide for the Fastly_Cdn module for Adobe Commerce.
Block traffic by country
For the Adobe Commerce on cloud infrastructure store, the most effective way to block traffic by country(s) is adding an ACL for Fastly in the Commerce Admin.
- In the Commerce Admin, navigate to Stores > Configuration > Advanced > System > Full Page Cache > Fastly Configuration.
- Select the countries and configure blocking using ACL as described in the Blocking guide for the Fastly_Cdn module for Adobe Commerce.
Block traffic by user agent
To establish blocking based on user agent, you need to add a custom VCL snippet to your Fastly configuration. To do this, take the following steps:
- In the Commerce Admin, navigate to Stores > Configuration > Advanced > System > Full Page Cache.
- Then Fastly Configuration > Custom VCL Snippets.
- Create the new custom snippet as described in the Custom VCL snippets guide for the Fastly_Cdn module. You can use the following code sample as an example. This sample disallows traffic for the
AhrefsBotuser agent.
name: block_bad_useragents
type: recv
priority: 5
VCL:
if ( req.http.User-Agent ~ "(AhrefsBot)" ) {
error 405 "Not allowed";
}
Block Traffic by JA3/JA4/OH signatures (Grab the JA3, JA4 and OHFP values from the Newrelic)
-
Create a dictionary: Navigate to Admin > Store > Configuration > System > Full page cache > Fastly configuration > Edge Dictionary and create this sample block:
code language-none #table ja3_blocklist: table ja3_blocklist { "********************************": "********************************", } #table ja4_blocklist: table filter_bad_ja4 { "************************************": "************************************", } -
Then add a VCL to block any JA3, JA4 listed in the above-defined table:
code language-none name: block_traffic_ja3_ja4 type: recv priority: 5 VCL: if (req.restarts == 0 && fastly.ff.visits_this_service == 0) { if(table.contains(ja3_blocklist, tls.client.ja3_md5)){ error 403; } if(table.contains(ja4_blocklist, tls.client.ja4)){ error 403; } } -
Block sample based on OHFP:
code language-none #table ohfp_h2fp_blocklist table ohfp_h2fp_blocklist { "xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx":"xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx:xx", } -
Then add a VCL to block any OHFP isted in the above-defined table:
code language-none # Snippet block_ohfp_h2fp name: block_ohfp_h2fp type: recv Priority: 5 if (table.contains(ohfp_h2fp_blocklist, fastly_info.oh_fingerprint)) { error 403 "Forbidden"; }
Rate Limiting (experimental Fastly functionality)
There is an experimental Fastly functionality for Adobe Commerce on cloud infrastructure which allows you to specify the rate limit for particular paths and crawlers. Please reference the Fastly module documentation for details.
The functionality must be extensively tested on staging, before being used on production, because it might block legitimate traffic.
Recommended: consider updating robots.txt
Updating your robots.txt file could help to keep certain search engines, crawlers, and robots from crawling certain pages. Examples of pages that should not be crawled are search result pages, checkout, customer information and so on. Keeping robots from crawling these pages could help to decrease the number of requests generated by those robots.
There are two important considerations when using robots.txt:
- Robots can ignore your
robots.txt. Especially malware robots, that scan the web for security vulnerabilities, and email address harvesters used by spammers will pay no attention. - The
robots.txtfile is a publicly available file. Anyone can see what sections of your server you don’t want robots to use.
The basic information and default Adobe Commerce robots.txt configuration can be found in the Search Engine Robots article in our developer documentation.
For general information and recommendations about robots.txt, see:
- Create a robots.txt file by Google Support
- About /robots.txt by robotstxt.org
Work with your developer and/or SEO expert to determine what User Agents you want to allow, or those you want to disallow.
Related reading
- Product Specific Licensing Terms for Adobe Commerce on Cloud
- Custom VCL for blocking requests in the Commerce on Cloud Guide