Emergency server help: get in touch

Imunify360 Whitelist IP and Countries from the CLI: Commands

Use imunify360-agent ip-list and country-list commands to whitelist and blacklist addresses, networks and countries, remove greylist blocks, create RBL exemptions, script bulk imports, and confirm the entries are active in the firewall.

Published Updated 6 min read

Imunify360’s WHM plugin exposes whitelists and blacklists under the Firewall tab, but for anything beyond a couple of entries the command line is quicker, scriptable and works over SSH when the panel is slow or unreachable. The agent’s imunify360-agent binary manages four kinds of list: a per-server local list with white, black, grey and a drop purpose, a country list, an RBL exemption list, and a set of ignore lists for scanners. Understanding which one a situation needs saves a lot of time, especially when a customer’s office or a monitoring service keeps getting blocked.

Short answer: Whitelist an address with imunify360-agent ip-list local add --purpose white 203.0.113.5 --comment "office", a network with the same command and CIDR notation, and a country with imunify360-agent country-list add --purpose white GB. Clear a temporary block with imunify360-agent ip-list local delete --purpose grey 203.0.113.5, list entries with imunify360-agent ip-list local list --purpose white, and confirm the ipset with imunify360-agent ip-list local list --by-ip 203.0.113.5.

Understand the list purposes

The local list holds entries added on this server. The white purpose bypasses all blocking, including the WAF and WebShield challenges when the full-access option is set; black denies the address outright; grey is where the agent places addresses it has temporarily blocked after suspicious behaviour, and drop discards traffic without response. Country lists work the same way with ISO two-letter codes. The RBL whitelist exempts addresses from blocks that originate in the vendor’s reputation feeds, which is different from a local block and is the reason a local whitelist sometimes appears not to work.

Whitelist and blacklist addresses

Add, inspect and remove single addresses or networks:

imunify360-agent ip-list local add --purpose white 203.0.113.5 --comment "office static IP"
imunify360-agent ip-list local add --purpose white 198.51.100.0/24 --comment "monitoring"
imunify360-agent ip-list local add --purpose black 192.0.2.77 --comment "brute force"
imunify360-agent ip-list local list --purpose white
imunify360-agent ip-list local delete --purpose white 198.51.100.0/24

Add --full-access to a white entry when the address must also skip WAF rules and captcha challenges, which is appropriate for an administrator’s own address but not for a customer’s whole office. Entries accept IPv6 as well. The --expiration option takes a Unix timestamp and is useful for time-limited whitelists such as a penetration tester’s address for the duration of an engagement.

Clear greylist blocks and RBL listings

When a user reports being blocked, find them across every list first:

imunify360-agent ip-list local list --by-ip 203.0.113.5
imunify360-agent ip-list local delete --purpose grey 203.0.113.5
imunify360-agent incident list --by-ip 203.0.113.5 --limit 5

The incident list explains why the block happened, which is the information the customer needs. If the address appears nowhere locally yet is still blocked, the block comes from the vendor’s reputation feed; add it with imunify360-agent rbl-whitelist add 203.0.113.5 if that command exists on your build, or use imunify360-agent create-rbl-whitelist which generates exemptions for the server’s own addresses, and otherwise whitelist locally which takes precedence over the feed. Persistent legitimate traffic that keeps landing in the greylist, such as a backup server hammering SFTP, belongs on the white list permanently.

Country lists

Country-level rules are blunt but effective on servers with a purely regional customer base:

imunify360-agent country-list add --purpose white GB
imunify360-agent country-list add --purpose black KP
imunify360-agent country-list list
imunify360-agent country-list delete --purpose black KP

A whitelisted country skips reputation blocks for its addresses; a blacklisted one is denied entirely. Because geolocation databases lag behind IP reassignments, keep a local whitelist for known partner addresses even when their country is whitelisted, and never blacklist the country where your own monitoring or CDN nodes live. Blocking the country of a CDN’s edge nodes is a frequent cause of the site-loopback failures described in Fix WordPress cURL error 28 caused by Imunify360 or CSF.

Bulk import and scripting

For a long list of monitoring or partner ranges, feed a file through a loop:

while read -r ip; do
  [ -n "$ip" ] && imunify360-agent ip-list local add --purpose white "$ip" --comment "partner-ranges"
done < /root/partner-ranges.txt
imunify360-agent ip-list local list --purpose white --json | python3 -m json.tool | grep -c '"ip"'

Every command accepts --json for output that other tooling can parse. Keep the source file under version control so the whitelist can be rebuilt on a replacement server, and remember that entries added here are per server; a fleet needs the same loop run on each, or a central management setup.

Verify and pitfalls

Confirm an entry is effective by checking both the agent and the kernel:

imunify360-agent ip-list local list --by-ip 203.0.113.5
ipset list i360_white 2>/dev/null | grep -c 203.0.113.5
nft list set inet imunify360 white 2>/dev/null | grep -c 203.0.113.5

One of the last two matches depending on the firewall backend in use. Then test from the address itself if you can. The main pitfall is whitelisting an address in Imunify360 while CSF, still installed on the same server, holds it in csf.deny; check with csf -g too. Another is adding an address to the white list without --full-access and then wondering why the WAF still challenges it; that is by design, and the flag is the answer.

Imunify360 whitelist IP at a glance

Imunify360 Whitelist IP and Countries from the CLI summary card: Whitelist an address with imunify360-agent ip-list local add --purpose white 203.0.113.5 --comment "office", a network…
In short: Whitelist an address with imunify360-agent ip-list local add –purpose white 203.0.113.5 –comment “office”, a network with the same command and CIDR notation, and a country with imunify360-agent country-list add –purpose white GB.

Official documentation: Imunify360 documentation, cPanel & WHM documentation, Linux man pages.

Related guides: Fix Imunify360 missing from the WHM interface (enable-plugin and other causes) · Fix WordPress “cURL error 28: Failed to connect” caused by Imunify360 or CSF · Imunify360 in 2026: WAF by default, L7 rate limiting and Under Attack Mode tuning.

Frequently asked questions

Does an Imunify360 whitelist also bypass ModSecurity WAF rules?

Only when the entry is added with --full-access. A plain white entry prevents IP-level blocks and reputation denials but the WAF continues to inspect requests from that address.

How long does an Imunify360 whitelist take to apply?

Local list changes are pushed to the ipset or nftables set within seconds. Country list changes can take up to a minute while the agent rebuilds the country address sets.

Can I undo a whitelist or blacklist entry?

Yes. Run imunify360-agent ip-list local delete or country-list delete with the same purpose and value; the change is immediate and the incident history for that address is retained for reference.

Free website test

Is your website set up right?

Check SSL, security headers, redirects, robots.txt, sitemap, llms.txt and security.txt in one test. It takes about 30 seconds.