Restricting direct traffic & allowing FortiWeb Cloud IP addresses
Restricting direct traffic
Once you complete setting up FortiWeb Cloud, configure your application servers to only accept traffic from FortiWeb Cloud IP addresses.
- If CDN is enabled, make sure to accept traffic from all the IP addresses listed in the following tables, including the service management IPs and the scrubbing centers' IPs.
- If CDN is not enabled, configure to accept traffic from the service management IPs and the scrubbing center assigned to your application server.
However, it's recommended to accept traffic from all the following IP addresses, so that you don't need to go back and accept more IP addresses if you change the CDN status from disabled to enabled.
To know which scrubbing centers are assigned to your application, see How does FortiWeb Cloud choose regions?
Allowing FortiWeb Cloud IP addresses
If you have deployed a DDoS device or system in your environment, it's most likely that FortiWeb Cloud's behavior will be detected as DDoS attacks, because all the requests arriving at your application server have FortiWeb Cloud's IP addresses as their source IP addresses.
To avoid this, highly recommend you to add FortiWeb Cloud IP addresses to the allowlist of your DDoS device or system.
The IP addresses labeled offline in the following tables are backup IP addresses, which can be used when the other IP addresses fail to work.
View the IP addresses of your region in Global > Applications by clicking the Allow IP List button. A window will pop up displaying all Cloud Waf IPs that need to be added to the firewall. You can also filter for Platform, Name, and Domain Name by clicking Add Filter before clicking Allow IP List.
|
We have provided two web pages listing all of the IPv4 and IPv6 addresses of the FortiWeb Cloud scrubbing centers: https://www.fortiweb-cloud.com/ips-v4 and https://www.fortiweb-cloud.com/ips-v6. These URLs can be referenced on a FortiGate as a "Threat Feed" which is dynamically kept up-to-date by the firewall, and can be referenced in security policy. |
FortiWeb Cloud service management IP
The IP addresses of FortiWeb Cloud's services interacting with your application server |
3.123.68.65 |
FortiWeb Cloud scrubbing centers on AWS
Scrubbing centers |
IPv4 addresses |
IPv6 addresses |
ap-east-1: Asia Pacific (Hong Kong) |
18.166.240.188 18.167.155.174 16.163.110.210 18.167.190.240 16.163.212.249 18.166.175.52 18.162.227.141 |
2406:da1e:b:ae01:31b6:202a:2bbc:79da 2406:da1e:b:ae02:f3f4:38fa:d7a2:311a 2406:da1e:b:ae01:b1ae:20d2:703f:a868 2406:da1e:b:ae01:841e:27d4:4642:5f7f 2406:da1e:b:ae02:5b3d:9808:f840:b303 2406:da1e:b:ae01:b528:d77c:b017:a202 2406:da1e:b:ae02:52f5:30d5:fc8f:9e90 |
ap-southeast-1: Asia Pacific (Singapore) |
54.179.22.186 18.140.21.233 18.136.170.71 13.214.45.126 52.77.123.220 13.215.241.201 13.251.178.146 52.220.49.161 13.228.126.80 |
2406:da18:ad1:1101:da8c:5ad5:b55e:5f54 2406:da18:ad1:1102:4019:44c9:e3ab:b2f6 2406:da18:ad1:1101:b6ad:34de:de05:5ef3 2406:da18:ad1:1102:9a1c:767e:1e67:4763 2406:da18:ad1:1101:f6f4:fec3:429b:cf21 2406:da18:ad1:1102:bcae:7ecd:6d98:a06 2406:da18:ad1:1101:5dbb:604b:b5b6:b092 2406:da18:ad1:1101:7215:137a:bfff:f7 2406:da18:ad1:1102:2df2:b6fb:c048:dcac |
ap-southeast-2: Asia Pacific (Sydney) |
13.236.106.64 13.237.77.127 13.237.159.2 54.79.207.53 13.54.172.164 13.210.41.167 54.252.85.192 54.153.144.173 52.62.180.47 |
2406:da1c:607:e201:df9c:6ba:4f89:6fd9 2406:da1c:607:e202:a298:e79a:d84b:cabc 2406:da1c:607:e201:dbc1:8ad8:624d:f906 2406:da1c:607:e202:30fe:b581:362b:e8b2 2406:da1c:607:e201:b8e0:4de5:dcdf:209c 2406:da1c:607:e202:9969:3b23:e201:e814 2406:da1c:607:e201:6e34:9ff2:ecb:c8eb 2406:da1c:607:e201:c0e7:f44c:7012:266a 2406:da1c:607:e202:1f5c:8b63:fbf2:28ea |
ap-south-1:Asia Pacific (Mumbai) |
15.207.198.87 15.206.52.49 3.109.248.211 3.109.17.189 13.234.208.160 3.108.143.49 43.204.40.78 |
2406:da1a:31:d501:50e1:400b:5699:2427 2406:da1a:31:d502:c14e:dcc9:5307:e359 2406:da1a:31:d501:fc19:5e59:9804:b392 2406:da1a:31:d502:2eaf:153f:91b3:7dc0 2406:da1a:31:d501:8064:5da4:4a3:5458 2406:da1a:31:d502:f7cf:30d8:60f3:ba2b 2406:da1a:31:d501:a644:652c:8e74:fa57 |
ca-central-1: Canada (Central) |
52.60.112.90 99.79.174.29 3.97.158.98 3.97.249.50 3.99.18.71 99.79.119.81 99.79.85.123 15.223.11.8 3.99.0.8 |
2600:1f11:8c:9101:250e:bf5a:6646:e527 2600:1f11:8c:9102:abb2:7f29:6f98:ea53 2600:1f11:8c:9101:eb3:39f1:1815:884e 2600:1f11:8c:9102:411d:63f2:e5b4:5209 2600:1f11:8c:9101:d917:6c:8f07:f193 2600:1f11:8c:9102:729e:b7b1:34c:1e53 2600:1f11:8c:9101:86ea:d6ff:c7f0:ad44 2600:1f11:8c:9101:be54:e939:1483:fce6 2600:1f11:8c:9102:974e:4977:6617:28a |
eu-central-1: Europe (Frankfurt) |
3.121.49.99 3.120.253.91 18.192.229.245 18.192.220.216 18.192.64.32 3.125.233.133 35.156.146.120 35.158.251.28 3.69.183.166 3.69.202.9 18.184.56.149 3.72.137.154 3.127.31.213 52.58.147.238 18.198.141.132 3.76.87.93 |
2a05:d014:f3c:6c01:cf53:8a1:630:517e 2a05:d014:f3c:6c02:30e:dcf4:4b91:8e01 2a05:d014:f3c:6c01:8571:cefb:8d43:6d3c 2a05:d014:f3c:6c02:2712:69b4:cf65:e99e 2a05:d014:f3c:6c01:99d0:8c50:ae51:99ac 2a05:d014:f3c:6c02:58:3e12:a98a:df9f 2a05:d014:f3c:6c01:24c5:1d8d:b3be:2785 2a05:d014:f3c:6c02:2490:b345:e759:f43f 2a05:d014:f3c:6c01:e799:dd65:59c7:d4b7 2a05:d014:f3c:6c02:af21:546d:5054:a7e3 2a05:d014:f3c:6c01:ae76:adc3:661d:29dc 2a05:d014:f3c:6c02:9041:85c2:24f5:592f 2a05:d014:f3c:6c01:5e7a:1eba:64:30ce 2a05:d014:f3c:6c02:3b5d:afaa:1d4:b8f1 2a05:d014:f3c:6c01:4508:b102:6ece:86cf 2a05:d014:f3c:6c02:f2cd:f562:1b85:dd7e |
eu-west-1: Europe (Ireland) |
54.72.157.51 52.214.147.155 54.78.90.129 54.217.132.119 34.253.16.245 54.78.225.214 52.31.156.114 3.250.247.85 34.241.85.225 52.50.196.213 18.200.105.101 |
2a05:d018:77c:d901:e1bc:f536:85bb:5caa 2a05:d018:77c:d902:f60f:e089:c3ca:3743 2a05:d018:77c:d901:4f37:924f:6ea2:5952 2a05:d018:77c:d902:6605:9bef:2ca3:f220 2a05:d018:77c:d901:67a0:bb76:3597:b7f7 2a05:d018:77c:d902:a9ce:15bb:562f:7549 2a05:d018:77c:d901:7254:99fb:fee0:91c7 2a05:d018:77c:d901:12e0:4d59:ac0d:cceb 2a05:d018:77c:d902:608:4e5c:54c2:d4e2 2a05:d018:77c:d901:1509:1b4a:e9a1:8ce7 2a05:d018:77c:d902:4573:afbf:daf7:730a |
eu-west-2: Europe (London) |
18.130.214.145 3.9.251.147 18.134.173.119 52.56.112.105 3.11.174.119 3.11.12.196 3.11.216.166 18.168.230.94 18.130.48.8 18.170.8.138 18.168.188.14 |
2a05:d01c:64d:7001:5b0c:f5e1:f737:b883 2a05:d01c:64d:7002:e25b:55e:1564:21fd 2a05:d01c:64d:7001:7f27:28fe:f43b:e55b 2a05:d01c:64d:7002:a0b0:a076:53b2:31e3 2a05:d01c:64d:7001:dfb8:aa3d:3848:f26b 2a05:d01c:64d:7002:c77f:a8c8:7655:1cd1 2a05:d01c:64d:7001:d15a:3e1b:337f:92d7 2a05:d01c:64d:7001:1e54:38a8:2653:4d95 2a05:d01c:64d:7002:8a95:b846:2f49:ca5b 2a05:d01c:64d:7001:641e:9663:739a:33ca 2a05:d01c:64d:7002:e585:8452:6fea:c326 |
eu-west-3: Europe (Paris) |
35.181.28.236 52.47.112.113 13.36.206.34 15.188.2.107 35.181.84.20 13.36.245.25 35.181.130.113 13.36.99.148 35.180.221.56 13.39.124.108 13.36.113.40 |
2a05:d012:c22:9a01:77e0:8f18:fb7e:fb1e 2a05:d012:c22:9a02:fa49:295e:27d5:1821 2a05:d012:c22:9a01:d23a:98af:1e6c:c9fb 2a05:d012:c22:9a02:fc4a:2226:47cd:66f5 2a05:d012:c22:9a01:6fbc:eb92:7eb5:fa4a 2a05:d012:c22:9a02:a1ca:7e27:28f7:bbba 2a05:d012:c22:9a01:f7c8:b42:a1d9:1c5e 2a05:d012:c22:9a01:85ed:d68a:483:26c7 2a05:d012:c22:9a02:daa8:f4b8:3356:98e6 2a05:d012:c22:9a01:335f:ba6:f76:df50 2a05:d012:c22:9a02:b26d:7261:bc18:48c8 |
eu-south-1: Europe (Milan) |
15.161.173.116 15.161.10.152 15.161.215.247 15.161.76.114 18.102.20.169 18.102.26.204 35.152.36.51 15.161.83.238 18.102.19.162 18.102.146.236 15.160.64.40 |
2a05:d01a:9f2:1701:bd84:9314:f93:b2f 2a05:d01a:9f2:1702:aca5:5d4d:1995:50d 2a05:d01a:9f2:1701:4d5b:f1a8:d291:5a84 2a05:d01a:9f2:1702:8e71:e939:c954:1608 2a05:d01a:9f2:1701:eb19:dfb0:2ba0:9782 2a05:d01a:9f2:1702:306c:6cac:b6f3:d03e 2a05:d01a:9f2:1701:9734:6666:5d:40ec 2a05:d01a:9f2:1701:53ba:32e9:7ef2:198f 2a05:d01a:9f2:1702:dead:f4ac:dc23:9d6e 2a05:d01a:9f2:1701:b077:f47d:2a5c:96f2 2a05:d01a:9f2:1702:8ba8:740e:184a:260e |
Il-central-1: AWS Israel (Tel Aviv) |
51.16.118.151 51.17.26.125 51.16.198.214 51.16.192.242 |
2a05:d025:c86:1701:39b:f35d:2126:5c85 2a05:d025:c86:1702:3be9:6a28:de24:3589 2a05:d025:c86:1701:1eb6:57b5:dfe6:4cfb 2a05:d025:c86:1702:4ddf:2b90:a945:ea28 |
us-east-1: US East (N. Virginia) |
3.226.118.124 3.210.115.14 54.144.250.206 23.21.42.132 34.233.191.126 54.198.165.25 3.228.64.186 3.231.16.50 54.156.35.181 52.22.134.181 3.224.233.117 174.129.221.93 3.214.245.110 3.225.188.145 18.214.30.87 34.206.129.226 100.25.206.91 52.44.217.91 |
2600:1f18:1492:1701:5ebe:2322:bb2e:1c87 2600:1f18:1492:1702:af7a:a957:dd53:be07 2600:1f18:1492:1701:b42b:c8b6:9d9b:5752 2600:1f18:1492:1702:eebf:68e3:7e83:a9a6 2600:1f18:1492:1701:6910:cfcf:2f0a:9102 2600:1f18:1492:1702:d556:77ec:34ad:4cbb 2600:1f18:1492:1701:e54f:59c6:7114:2878 2600:1f18:1492:1702:e618:cb8e:f4b5:4ba4 2600:1f18:1492:1701:c65b:f5d9:784d:d3d6 2600:1f18:1492:1702:7e65:574b:1013:7209 2600:1f18:1492:1701:c800:b061:afc1:5a2a 2600:1f18:1492:1702:aa32:a7b0:116f:1b69 2600:1f18:1492:1701:7c58:5331:25e3:3343 2600:1f18:1492:1702:b3ff:2b1d:d9a7:9e88 2600:1f18:1492:1701:6451:e2d7:11bc:da4d 2600:1f18:1492:1702:9f57:b34f:ef00:726 2600:1f18:1492:1701:7906:404b:ba59:dff3 2600:1f18:1492:1702:524:eda4:749f:26d6 |
us-east-2: US East (Ohio) |
3.19.24.89 3.13.39.239 3.131.242.28 18.188.127.1 3.139.50.156 18.189.50.81 52.15.38.41 3.129.83.41 3.13.53.24 18.224.115.39 3.134.201.211 |
2600:1f16:160:aa01:f753:ce95:4466:884f 2600:1f16:160:aa02:d842:2cf8:964c:b004 2600:1f16:160:aa01:4584:fec1:ab59:6bd4 2600:1f16:160:aa02:5629:28f1:196d:acbe 2600:1f16:160:aa01:8769:8d0b:d2de:28d4 2600:1f16:160:aa02:2752:5869:d2af:3811 2600:1f16:160:aa01:4b21:e5ce:3c8e:c368 2600:1f16:160:aa01:ad18:2fce:479f:a78f 2600:1f16:160:aa02:3a6:c48:a903:de9 2600:1f16:160:aa01:1749:9160:1c6a:5e9f 2600:1f16:160:aa02:b510:7929:d3e6:12e6 |
us-west-1: US West (N. California) |
13.56.33.144 52.52.208.2 52.8.219.206 52.9.219.121 54.193.111.235 52.9.188.134 52.9.57.162 184.169.166.201 54.176.39.164 |
2600:1f1c:b97:d801:6efe:3295:e11a:e6b 2600:1f1c:b97:d802:d788:18f9:b8e3:a981 2600:1f1c:b97:d801:ff83:8b03:7a29:5981 2600:1f1c:b97:d802:fe8f:1a5d:5d1:1c6b 2600:1f1c:b97:d801:e6c4:34b2:d9cb:4147 2600:1f1c:b97:d802:d073:2d49:432:2aa6 2600:1f1c:b97:d801:e507:2d99:87b1:b666 2600:1f1c:b97:d801:8fb0:a6dd:1f2a:54db 2600:1f1c:b97:d802:43f8:ddcc:da5e:b21e |
us-west-2: US West (Oregon) |
54.70.126.22 54.186.80.150 35.160.55.58 44.241.247.81 35.85.67.11 35.155.214.19 44.227.236.231 18.224.115.39 3.134.201.211 44.225.123.220 34.214.132.181 |
2600:1f14:b5a:da01:d056:d959:eb59:49e2 2600:1f14:b5a:da02:88c1:8365:8baf:677 2600:1f14:b5a:da01:a32:4cac:f337:9c00 2600:1f14:b5a:da02:5a8e:d30:ff37:18a9 2600:1f14:b5a:da01:ab8a:9684:cd53:598d 2600:1f14:b5a:da02:fdfa:2560:ae51:20ee 2600:1f14:b5a:da01:df9a:f157:a04a:b1a1 2600:1f16:160:aa01:1749:9160:1c6a:5e9f 2600:1f16:160:aa02:b510:7929:d3e6:12e6 2600:1f14:b5a:da01:a4c6:ab36:7bf9:915d 2600:1f14:b5a:da02:2a4e:edb1:7409:dfb9 |
sa-east-1: South America (Sao Paulo) |
54.207.7.119 18.231.48.25 54.207.227.252 177.71.170.92 18.228.169.208 54.207.65.147 52.67.36.82 18.229.224.63 15.229.95.152 |
2600:1f1e:653:3201:e41:9bc0:8071:cec0 2600:1f1e:653:3202:2261:f67:9605:ebbe 2600:1f1e:653:3201:eac8:161d:c0a:6915 2600:1f1e:653:3202:3615:6e2c:7b0c:85c9 2600:1f1e:653:3201:8fed:9a99:d38e:4855 2600:1f1e:653:3202:d9f7:e5d7:ab2f:e684 2600:1f1e:653:3201:b266:d210:941f:46bb 2600:1f1e:653:3201:6d62:b616:3070:869f 2600:1f1e:653:3202:cad1:1b69:28e2:ccea |
FortiWeb Cloud scrubbing centers on Azure
Scrubbing centers |
IPv4 addresses |
---|---|
West Europe |
52.149.70.62 52.149.99.16 20.86.129.248 20.86.49.155 51.124.233.151 20.4.62.24 20.4.62.25 13.95.206.25 13.95.206.33 104.40.255.125 13.80.68.18 13.80.71.152 |
West US2 |
40.90.196.194 40.90.208.131 20.29.202.53 20.29.202.44 20.29.202.61 20.230.223.218 20.230.221.119 |
East US |
40.90.225.162 40.90.250.88 52.151.250.58 20.62.192.27 20.127.74.161 20.127.74.103 20.127.74.143 172.190.214.230 172.190.214.225 |
East US2 |
20.69.235.177 20.81.153.33 20.110.208.49 20.110.186.177 20.14.167.255 20.65.95.32 20.10.155.255 |
Australia East |
20.70.160.47 20.70.152.97 20.248.200.0 20.248.200.83 20.28.181.79 20.28.181.228 |
Brazil South (São Paulo State) |
20.195.163.139 20.197.225.122 20.226.106.176 20.226.106.172 4.228.89.120 4.228.89.123 |
Brazil South3 |
4.228.89.120 4.228.89.123 |
Canada Central |
20.63.56.203 20.63.58.199 20.48.236.10 20.48.236.225 20.220.63.30 20.220.59.101 |
FortiWeb Cloud scrubbing centers on Google Cloud
Scrubbing centers |
IPv4 addresses |
---|---|
us-west1 (Oregon) |
34.83.129.59 34.82.233.199 34.83.15.189 34.168.224.208 |
us-east1 (South Carolina) |
34.74.199.185 35.227.112.86 34.148.6.49 34.138.149.79 |
europe-west3 (Frankfurt) |
35.242.209.119 35.242.218.171 34.159.173.59 35.198.124.236 |
europe-west8 (Milan) |
34.154.63.30 34.154.60.54 34.154.148.78 34.154.84.52 |
FortiWeb Cloud scrubbing centers on OCI
Scrubbing centers |
IPv4 addresses |
---|---|
US East (Ashburn) |
193.122.181.94 129.159.75.103 129.159.74.168 (offline) |
US West (Phoenix) |
158.101.43.252 158.101.43.253 129.146.233.205 (offline) |
Germany Central (Frankfurt) |
158.101.176.179 193.122.55.66 132.145.248.29 (offline) |