> For the complete documentation index, see [llms.txt](https://docs.link11.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.link11.com/product-guides/network-ddos-v3/interface/blocklist.md).

# Blocklist

## Blocklist

The Blocklist page displays all IP addresses that have been blocked by Network DDoS. It provides a world map showing the geographic distribution of blocked sources and a table with full details on each blocked IP.

## World Map

The map displays countries shaded by the number of blocked IPs originating from that country during the selected time range. Countries with higher concentrations of blocked sources appear with stronger shading.

<figure><img src="/files/cscx5vempNnWfiMCB27o" alt=""><figcaption></figcaption></figure>

{% hint style="info" %}
This page currently shows IPv4 data only. A future release will add data for IPv6 as well.
{% endhint %}

***

## **Search**

Use the search box to find a specific IP address. This is an IP address search — it does not support full-text search on other fields.

<figure><img src="/files/dcor3XyfNemM4Ma2cHu8" alt=""><figcaption></figcaption></figure>

{% hint style="danger" %}
These fields are not supported for search::

* Attacker ISPs
* Countries
* Status
* Dates
  {% endhint %}

***

## **IP List**

Displays all IPs that were determined to be malicious by Network DDoS.

<figure><img src="/files/ScG92vGcSUw14kumkYg8" alt=""><figcaption></figcaption></figure>

### Table Columns

| Column         | Description                                                        |
| -------------- | ------------------------------------------------------------------ |
| Date           | When the IP was blocked.                                           |
| Destination IP | The protected IP address that was being attacked by this source.   |
| Attacker IP    | The source IP address that was blocked.                            |
| Attacker ISP   | The internet service provider associated with the attacker IP.     |
| Country        | The country associated with the attacker IP.                       |
| Status         | Whether the IP is currently **Blocked** or has been **Unblocked**. |

The dropdown above the table can be set to:

* **Show all IPs** — displays both currently blocked and previously unblocked IPs.
* **Show blocked IPs only** — displays only IPs that are still currently blocked.

## Unblocking IPs

### Bulk Unblock

The **Unblock all IPs that were blocked in the previous time period** control allows administrators to unblock all IPs blocked within a selected time window (e.g., the last 30 minutes). Select the window from the dropdown and click **Unblock** to apply.

### Unblocking Individual IPs

Each row with a currently blocked IP shows an **Unblock** option. Clicking this removes the block for that IP immediately without a page refresh.

{% hint style="info" %}
The Blocklist shows IP-level blocks applied by the mitigation system. To prevent specific IPs from ever being blocked, add them to the Blacklist in [Access Control](/product-guides/network-ddos-v3/interface/access-control.md)
{% endhint %}
