@SrWebDeveloperNov 21.2009 — #OP: Please be informed - if the visitor comes through a proxy or firewall on their end their WAN IP might be the same as anyone else on their LAN. So you might intend to block one user but might end up blocking many sharing that IP. Plus if your filter allows wildcards to ban ranges, one typo and you could ban an entire class C, B or huge block of unintended addresses with one unnoticed typo. And even proxy servers can be used to bypass an IP ban anyway unless you implement an anti-blocking script. In short, there are a few notable potential headaches if this kind of policy is not applied sensibly and carefully.
@NogDogNov 21.2009 — #OP: Please be informed - if the visitor comes through a proxy or firewall on their end their WAN IP might be the same as anyone else on their LAN. So you might intend to block one user but might end up blocking many sharing that IP. Plus if your filter allows wildcards to ban ranges, one typo and you could ban an entire class C, B or huge block of unintended addresses with one unnoticed typo. And even proxy servers can be used to bypass an IP ban anyway unless you implement an anti-blocking script. In short, there are a few notable potential headaches if this kind of policy is not applied sensibly and carefully.
-jim[/QUOTE]
I was under the impression from the original post that the OP wanted to whitelist one or a small number of IPs, not blacklist a limited number or range of IP addresses.
In either case, this could also be handled at the web server level such as limiting access to a directory via a .htaccess entry (if Apache), though I'd have to do a little Googling to come up with the syntax for that.
@SrWebDeveloperNov 24.2009 — #I was under the impression from the original post that the OP wanted to whitelist one or a small number of IPs, not blacklist a limited number or range of IP addresses.[/quote]
Understood, the implications I listed work in reverse, too, i.e. you can let a whole LAN segment in if their caching proxy is bound to a single IP, for example. The main point is using IP's is subject to consequences, so be aware and carefully setup any filters. That's all. ?