Drupal is a registered trademark of Dries Buytaert
Release: Excel Serialization 2.1.2 Minor update available for module xls_serialization (2.1.2). Release: Time Zone Field 8.x-1.14 Minor update available for module tzfield (8.x-1.14). Module Revived: Entity API 8.x-1.7 Module entity updated after 17 months of inactivity (8.x-1.7). Release: Varbase - The Ultimate Drupal CMS Starter Kit (Bootstrap Ready) 10.1.2 Minor update available for distribution varbase (10.1.2). Release: MCP Sentinel 2.8.0 Minor update available for module mcp_sentinel (2.8.0). Release: Vartheme Bs5 4.1.1 Minor update available for theme vartheme_bs5 (4.1.1). Release: Varbase Heroslider 1.1.3 Minor update available for module varbase_heroslider (1.1.3). Release: Varbase Demo 1.1.2 Minor update available for module varbase_demo (1.1.2). Release: Varbase Dashboards 2.0.3 Minor update available for module varbase_dashboards (2.0.3). Security Coverage: Role Aware Maxlength Module role_aware_maxlength now has official Drupal security advisory coverage.

Ban

1,608 sites Security covered
View on drupal.org

This module allows site administrators to block specific IP addresses from accessing the site. It is designed to be fast and lightweight, intercepting requests quickly to help mitigate attacks.

Ban was a core module from Drupal 8 to 11 and has moved to contrib for Drupal 12.

#1570102: [Policy] Deprecate Ban module

Ban allows administrators to ban visitors or requests to their site from individual IP addresses.
The Ban module is made to be extremely fast and lightweight, so that in cases of DDoS the Ban middleware intercepts fast and with little memory footprint.

Post-Installation

To ban an IP address

  1. Navigate to /admin/config/people/ban.
  2. Enter an IP address (for example, 10.0.0.1).
  3. Click Add.

Drupal will prevent you from banning your own IP address.

To remove the ban from an IP address in the UI

  1. Navigate to the ban page (see above).
  2. Beside an IP address, click Delete.

Ban Drush (drush) & Drupal CLI (dr) Commands

Available commands for the "ban" namespace:
  ban:ban        Ban an IP address.
  ban:flush      Unban all IP addresses.
  ban:list       List all banned IP addresses.
  ban:unban      Unban a specific IP address.
  ban:unban-all  Unban all IP addresses.

(Drupal CLI support from >= 1.1.0 #3606943: Add dr support in Ban)

  • Perimeter module uses ban to block IPs that accessed configured URLs
  • Crowdsec module uses ban to ban IPs by attack signals
  • Autoban module allows automatizing IP ban using watchdog table by the module rules.
  • For more advanced features and sophisticated levels of IP based protection, it is also worth considering system installed alternatives such as fail2ban

Alternative modules

Activity

Tracked releases
7
Tracked since
Jul 2025
Latest release
4 weeks ago
Releases (12 mo)
5 ▲ from 2
Maintenance
Active

Release Timeline

Releases

Version Type Release date
1.1.0 Stable Jul 17, 2026
1.1.0-beta3 Pre-release May 7, 2026
1.1.0-beta2 Pre-release Apr 2, 2026
1.1.0-beta1 Pre-release Mar 19, 2026
1.1.x-dev Dev Feb 24, 2026
1.0.0 Stable Jul 30, 2025
1.0.x-dev Dev Jul 25, 2025