Google Project Shield
-
Google Project Shield is a program to protect at risk journalists, such as myself. In essence, we point the A Record to Google and they handle the rest, but it is more of mirroring than being hosted by them. This is the link to their instructions for the Firewall. NTP is enabled and Use the X-Forwarded-For HTTP header is selected. It logs the Google IP correctly as well as the one I use to log in from at home. Nothing has been entered into the Trusted Proxies box. I also run MFA for myself, as admin, only.
Project Shield has three dedicated IP ranges:
35.235.224.0/20
34.96.0.0/20
34.127.192.0/18From Project Shield, “When you set up your firewall rules, you can limit them to these ranges. Please make sure all three ranges are included in your firewall allow list. Other IP ranges should be denied access to your origin, by setting a catch-all firewall rule for traffic not matching the Shield ranges.”
Is there somewhere in Wordfence I handle this? If not, could you advise me how to accomplish this in .htaccess utilizing the CIDR ranges above?
Thanks!
- The topic ‘Google Project Shield’ is closed to new replies.