Can I block VPNs and proxies, not just countries?
Yes. A rule can act on what an address is — a datacentre or hosting address, a VPN exit node, an open proxy, a Tor exit node or a known abuser — as well as where it comes from, including the AS number and the network operator behind it.
Won't blocking VPNs catch real customers?
That's exactly why there are signals for what not to block: corporate and privacy relays, verified crawlers, mobile networks and satellite networks. "Possible VPN" is offered separately from a confirmed VPN exit node, so you can be aggressive where you're certain and cautious where you aren't.
What stops a firewall rule taking my own customers offline?
Several things, deliberately. An address holding a valid line is never blocked automatically. A refused connection is turned away before a session exists, so it never consumes one of the user's allowed connections. If a country can't be determined the rule is skipped rather than enforced. And you can test a real address against your rules before anything depends on the answer.
Do I have to turn the kernel firewall on?
No. It's optional and off by default. When you do turn it on it starts in monitor mode, where it blocks nothing and simply records what it would have done — including how much of that would have been your own customers. You enforce only when the evidence from your own server says you should, and switching it off releases everything it holds.
Can a rule apply to only some accounts?
Yes. Rules can target everyone, restreamers only, everyone except restreamers, MAG receivers, Active Code devices, any device, ordinary subscriptions only, or specific users you name.
How do I know what a rule will actually do?
Every rule is written back to you as a plain sentence before you save it, and you can test a real address against your rules. Rules can also carry a note explaining why they exist — which matters more than it sounds when you revisit them months later.
Will you tell me the exact detection thresholds?
The thresholds are yours to set — how many events, over what window — so they fit your traffic. We don't publish the defaults here, because a public page is read by everyone, including the people you're being protected from. Ask us directly and we'll go through it.