Not every attack requires sophistication — many internet IPs are well-known attack sources: botnets, spam servers, automated scanners. cPGuard IPDB Firewall uses a real-time database of malicious IPs to block them before they can touch any website or service on the server. Rather than implementing complex rate-limiting rules or running heavy WAF analysis on every connection, IPDB works at the operating system level to instantly drop packets from known-bad sources.
cPGuard IPDB contains 40,000+ malicious IPs updated in real time via collective intelligence from servers and partners worldwide — an IP that attacks any one server gets shared and blocked across all cPGuard servers within hours, providing you with the latest threat intelligence automatically.
What is IPDB and how does it work?
IPDB (IP Database) collects IP addresses confirmed as malicious sources. These include botnets (compromised machines used to attack others), spam servers sending bulk email and phishing campaigns, port scanners probing for vulnerabilities, DDoS amplifiers that reflect traffic toward targets, and credential stuffers attempting to break into accounts using stolen username/password lists. cPGuard IPDB operates at the nftables firewall level — before the web server, mail server, or any application on the server. Packets from listed IPs are dropped instantly with zero application-layer CPU cost, making it far more efficient than blocking at the application level.
The technical implementation is crucial to understand: when a request arrives at your server, the kernel-level nftables firewall checks the source IP against the IPDB blocklist before Apache, Nginx, PHP, or your application code even touches it. If the IP matches, the packet is dropped entirely. This means blocked traffic never consumes server resources, no log entries are created by your application, and performance is unaffected.
Collective Intelligence — strength through global networks
What makes cPGuard IPDB different from a static blocklist is Collective Intelligence. The system works by connecting thousands of cPGuard-powered servers into a shared threat-intelligence network. When an IP attacks any cPGuard server anywhere in the world, the following process happens automatically:
- Attack detection — cPGuard identifies an attack from a specific IP (brute force, DDoS payload, scan traffic, etc.)
- Data submission — The suspicious IP is sent to OPSShield Cloud, cPGuard's centralized verification center
- Verification & analysis — OPSShield verifies the IP is indeed malicious (cross-referencing with threat feeds, behavior analysis)
- Global distribution — Once confirmed, the IP is added to IPDB and pushed out to all cPGuard servers worldwide
- Instant blocking — Your server and thousands of others block that IP automatically within minutes to hours
This collective approach is exponentially more powerful than a single maintained blocklist. An attacker's IP that becomes active today gets added to 40,000+ servers by tomorrow, making it nearly impossible for botnets to shift tactics quickly. Most public blacklists update once per day or less; IPDB updates in near-real-time as new threats emerge across the network.
Real-world blocking scenarios
To understand how IPDB protects your site in practice, consider these common attack types:
SSH Brute Force Attacks
A compromised botnet tries to log into your server's SSH port (22) by testing thousands of username/password combinations. Before cPGuard detects the attack pattern, traditional firewalls might log hundreds of failed login attempts, consuming CPU and disk I/O. With IPDB, the very first packet from that botnet IP is dropped by the kernel before SSH even receives it. The attack stops before it starts.
WordPress Admin Scanning
Attackers scan for WordPress installations by requesting `/wp-admin/`, `/wp-login.php`, etc. in bulk across thousands of IPs. These scanners send 10–50 requests per second from a single IP. Traditional solutions might block after detecting the pattern; cPGuard IPDB blocks the IP immediately if it's already on the known-bad list, and adds it if it's new, protecting all servers in the network.
Email Spam & Phishing
A spam server tries to use your mail server as a relay or spoof your domain. cPGuard detects this SMTP connection attempt and checks the sender's IP against IPDB. If it's a known spam source (and most are), the connection is dropped. Your server never processes the message, saving bandwidth and storage.
Additional firewall features included with cPGuard
IPDB is the core feature, but cPGuard includes several complementary security tools that work at the nftables level:
| Feature | What it does |
|---|---|
| GeoIP Country Block | Block all traffic from selected countries (useful if you don't serve certain regions) |
| Single-source DoS Prevention | Automatically block IPs sending more than a configurable threshold of requests per second |
| SYN Flood Protection | Prevent TCP SYN flood attacks that exhaust your server's connection tables |
| AI Bot Protection | Detect and block AI scrapers, bots, and automated crawlers that aren't search engines |
| Port Filtering | Close unused ports entirely to reduce your attack surface |
| Temporary Ban with Expiry | Set time-limited bans (e.g., ban for 1 hour, 24 hours, or 7 days) that auto-lift |
| Extended Rule Import | Import additional IP lists or custom rules from external threat feeds |
Runs before the web server: Because IPDB operates at the OS-level nftables, blocked IPs are dropped before Apache/Nginx even sees them — no application-layer CPU used at all. This is far more efficient than blocking in .htaccess (which still processes through Apache) or in PHP (which requires script execution). The performance difference is measurable, especially under attack.
AI-enhanced whitelist — preventing false positives
The biggest risk of any IP blocklist is blocking legitimate traffic by mistake. Some IP addresses are shared by millions of people — for example, corporate NAT gateways, university networks, or large ISP address blocks. If a single attacker uses a shared IP, a naive blocklist would block all users behind that gateway.
cPGuard mitigates this with an AI-enhanced whitelist that analyzes context before adding an IP to IPDB. The system considers factors like:
- IP reputation history — Is this IP known for legitimate use or primarily attack traffic?
- Attack pattern — Is the traffic pattern consistent with automated attacks, or could it be a misconfigured legitimate service?
- Geographic consistency — Do the attack patterns match the IP's geolocation?
- Fallback behavior — Has legitimate traffic been observed from this IP before?
By applying these heuristics, cPGuard significantly reduces false positives. Your real customers won't be blocked, even if their ISP shares an IP with a botnet.
Comparison: IPDB vs. other protection methods
To appreciate IPDB's value, compare it with alternatives:
IPDB vs. .htaccess rules
Blocking in .htaccess still requires Apache to process every request and evaluate rules. Under a heavy DDoS attack from 100 IPs, your server must evaluate 100 rule checks per request. With IPDB, those requests never reach Apache — they're dropped at the kernel level, so Apache CPU stays available for legitimate traffic.
IPDB vs. CSF/LFD (ConfigServer Firewall)
CSF offers local IP blocking but relies on your own server's logs to detect attacks. It can't see attacks happening to other servers, so it learns slower. cPGuard IPDB pools data from thousands of servers globally, so you benefit from threat intelligence across the entire network within minutes.
IPDB vs. WAF (Web Application Firewall)
A WAF analyzes HTTP payloads to detect SQL injection, XSS, file inclusion, etc. It's powerful but resource-intensive and application-specific. IPDB is lighter-weight and works for all protocols (HTTP, SSH, SMTP, FTP, etc.), making it a complementary layer. Many sites use both: IPDB for network-level attacks, WAF for application-level attacks.
Setting up IPDB on your hosting account
AsiaGB includes cPGuard IPDB on all shared hosting and VPS accounts. You don't need to install anything — it's active by default, blocking 40,000+ known-bad IPs immediately. However, you can customize it via the control panel:
- View blocked IPs — Check which IPs have been blocked and why
- Add custom blocks — Manually block specific IPs or ranges if needed
- Whitelist exceptions — If legitimate traffic is blocked (false positive), whitelist the IP to restore access
- Country blocking — Select countries to block entirely if you don't serve those regions
- Adjust thresholds — Set how many requests per second trigger a temporary DoS block
All configuration is done through the DirectAdmin control panel, with no command line access required. cPGuard handles the firewall rules automatically.
Frequently Asked Questions
What is IPDB?
IP Database (IPDB) is a database of IP addresses known to be sources of attacks, spam, DDoS or other malicious activity. cPGuard IPDB updates in real time and blocks these IPs at the firewall level before they can reach your website or server services. With 40,000+ entries updated from a global network, it provides highly effective protection against botnets, spammers, port scanners, and automated attackers.
How is IPDB different from a regular IP blacklist?
Regular blacklists update slowly (often daily) and draw from a single source, making them reactive rather than proactive. cPGuard IPDB uses collective intelligence from thousands of servers and partners worldwide — an IP that attacks any one server is shared and blocked across all cPGuard servers almost instantly. This means new threats are blocked globally within hours instead of days or weeks, and the threat database is continuously updated without requiring manual work on your part.
How does country blocking work?
Admins can block all traffic from countries with no real customers via GeoIP database in cPGuard, reducing the attack surface from high-risk regions. For example, if your business only serves Southeast Asia, you could block traffic from countries outside that region. This dramatically reduces the volume of attack traffic your server must process, freeing up resources for legitimate customers. GeoIP blocking is configured through the control panel with a simple dropdown of countries.
Does IPDB affect real users?
Risk is very low because IPDB targets confirmed attack-source IPs, not merely suspicious ones. The AI-enhanced whitelist reduces false positives by analyzing IP reputation, attack patterns, and historical legitimacy before blocking. Additionally, you can manually whitelist specific IPs if you discover a false positive, so legitimate traffic is never permanently blocked without your awareness and control.
What is the difference between DoS and DDoS, and does IPDB help?
DoS (Denial of Service) attacks come from a single IP or source; DDoS (Distributed Denial of Service) attacks come from many IPs simultaneously, often a botnet. IPDB helps with DDoS by blocking known botnet IPs that are already on the global blocklist, eliminating a portion of the attack traffic before it reaches your server. However, for large-scale DDoS attacks (especially those using dozens or hundreds of previously-unknown IPs), you may need additional protection from a CDN or dedicated anti-DDoS service that can absorb and filter attack traffic upstream.
Can I see which IPs are being blocked by IPDB?
Yes. cPGuard provides logging and a control panel interface to view blocked IPs, attack patterns, which IPDB entries matched, and GeoIP blocks. You can review blocked connections in real-time, add exceptions for specific IPs if needed, or whitelist entire IP ranges. This transparency helps you understand your site's security posture and troubleshoot legitimate users who may be inadvertently affected.
AsiaGB Hosting with cPGuard IPDB Firewall Protection
Every AsiaGB hosting account comes with cPGuard IPDB enabled, blocking 40,000+ malicious IPs worldwide automatically. Protect your website from DDoS, brute force, spam, and scanning attacks — starting from 500 THB/year on SSD storage.
View Hosting Plans