{{> header.html page_title="Settings · Exceptions" header_widgets=""}}

Exceptions

Carve out the legitimate traffic that BitFire's default rules would otherwise stop. Allow a single request shape to bypass the WAF, manage allowed IP and user-agent rules, and review or add blocked IPs that use BitFire's normal IP block path.

01 · Auto-tuning

Learning mode

Run the engine in observe mode only blocking obvious attacks for three days. BitFire will record the request shapes your real users generate and auto-add them as exceptions, dramatically reducing false positives once protection re-engages.

{{learn_complete}}
02 · WAF

Rule exceptions

Each row lets one specific request pattern bypass normal protection — useful when a legitimate URL trips a WAF signature. * means any value.

URL Parameter Rule type Rule number Action
03 · Allow list

Allowed IPs & user-agents

Add an IP address or user-agent string to the browser allow list. This page only adds allow rules here; blocked user-agents must be managed in Bot Control.

IP / user-agent Type Remove
04 · IP blocking

Blocked IPs

Block an IP address using BitFire's normal IP block path. These entries are separate from the browser allow list. Block log: {{block_log}}

IP Block reason Expires Remove
05 · Anonymous allow-lists

Anonymous allow-lists

Inputs that may bypass browser and bot verification. BitFire learns these automatically from verified browsers while learning mode is on; add or remove entries by hand below.

Anonymous GET parameters

Tracking or other harmless URL parameters allowed without browser / bot verification.

GET Parameter nameRemove

Anonymous PHP scripts

PHP files that may be accessed directly without browser or bot verification.

ScriptRemove

Anonymous POST URLs

Exact URL paths that may receive POST requests without browser or bot verification.

POST URL pathRemove

Anonymous AJAX actions

Extra admin-ajax.php actions runnable without browser or bot verification.

Ajax ActionRemove

Anonymous REST API endpoints

Extra wp-json endpoints accessible without browser or bot verification.

EndpointRemove
{{gtag}}