It is possible for us to block certain IP addresses from accessing our SFCC website storefront.
To block that suspicious IP address, we can use the following API, refer the given document for more details.
POST /organizations/{organizationId}/zone/{zoneId}/firewall/rules
Sample body:
{
"zoneId": "e4288c0a1f80fa5490b598d74c69bde4",
"type": "ip",
"action": "blocklist",
"values": ["123.123.0.0/16", "123.123.0.1/16", "123.124.127.0/24"]
}
The API provides the ability to use a blocklist to deny specific CIDR or IP addresses. The API can prevent known bad actors from accessing the storefront as they attempt to harm or access your web application.
Documentation Link: https://developer.salesforce.com/docs/commerce/commerce-api/guide/cdn-zones.html#ip-access-control
-----------------------
P.S. If we want to secure access to Business Manager, we can set the allowlist or blocklist from
Business Manager > Administration > Global Preferences > Security
