In my Google Analytics I’ve noticed over the past month or so a huge increase in site visits from China. I never get orders from China, so I’m not really interested in having site visitors from there using my bandwidth. Is there an effective way to block visitors from China from accessing my site without blocking legitimate customers from other places?
I’ve gotten slammed with China and Singapore visits also. I set a security rule in Cloudflare to block all traffic from both countries. It helped, but not 100%.
OK. I’m not using CloudFlare. I did block China in WHM using cPHULK Brute Force Protection and it temporarily took visits from China down to 0, but then they climbed back up again; so I an only assume they found a way around the block. Any further help on this would be appreciated. It appears someone in China is targeting CS-Cart stores.
All of the hits seem to be coming from a place called Lanzhou.
Any help here?
Same problem here. Lanzhou, Singapore and some other.
I’ve always had an issue since day one and since I only do business in the US, I am using CSF to block all other countries.
Update: Visitor count from Lanzhou went down to less than 5 after I blocked China in CSF, but I just looked again and the number has climbed to 27.
Is there anything else that can be done?
Any guesses as to what the purpose of these visits would be?
You may not be blocking all of China. It’s been a while since I set mine up so I can’t remember all of the steps but I set mine up where I only allowed/whitelisted US territories instead of entering all of the countries I wanted to block (allowing US IP’s list is smaller than blocking all other countries IP’s list). After I did this, I found that some IP’s in the US were still blocked and it was because the default number of IP entries was too low.
I like using CSF vs everything else because it blocks them from everything not just http.
Edit: The setting is LF_IPSET_MAXELEM. Default is 65536 and I set mine to 16777216 which is overkill for my situation. It will also depend on the reliability of the IP list you are using. I am using Maxmind.
OK thanks. Visitors from China are at 60 currently.
I’m being told the best way to block these is to use Cloudflare, so I’m going to be researching how to implement that. CSF appears to be doing zilch.
I’m now using Cloudflare. I’ve blocked China, as well as turning on Page Shield and Fight Bot Mode. Still currently showing 42 visitors from Lanzhou, China. Any other ideas?
Did you use the csf country deny…CC_DENY under firewall configuration in WHM…then “CN”.
And did you restart csf
Then wait at least an hour in case they are ghosts.
@johnbol1
Yes, I did all of that. Made no difference best I can tell.
I’m told that the settings I made in Cloudflare could take 24 hours to go into effect, so we’ll see. I’ll report back.