Docs

Allowlisting PulseKeeper

If your site sits behind a firewall or bot protection, it may block our checks. When that happens we cannot tell whether the site is up: visitors may see it fine while our probes get an error page.

How we notice a firewall

When a check comes back with 401, 403, 406, 429 or 503 and the response carries the fingerprints of a known firewall, we record it as blocked by a firewall instead of an outage. We recognise:

Firewall How we recognise it
Cloudflare cf-ray or cf-mitigated header, server: cloudflare, or its challenge page
Sucuri x-sucuri-id header or server: Sucuri
Imperva (Incapsula) x-iinfo header or an incap_ses cookie
Akamai server: AkamaiGHost

A blocked check is treated differently from an outage:

  • it opens a warning, not a critical incident: no SMS, and quiet hours hold it until morning;
  • it does not count against uptime or your SLA;
  • the monitor page shows which firewall is blocking us and the addresses to allow.

Our IP addresses

Checks come from these addresses, one per location:

  • 164.90.187.198 (Frankfurt)
  • 137.184.30.6 (New York)
  • 138.197.198.212 (San Francisco)

The same list is always available as plain text at https://pulsekeeper.io/ips and as JSON at https://pulsekeeper.io/ips.json, so you can automate it. Addresses change only when we add a location; the lists are updated at the same moment.

IPv4 or IPv6

By default every check connects over IPv4, so allowing our IPv4 addresses is enough. On plans that include it (see pricing) you can change this for the whole team in Settings → Organization → IP version, and for a single monitor in its Settings: IPv6 only, or automatic (IPv6 whenever the target has an IPv6 address). If you pick IPv6 or automatic, allow our IPv6 addresses as well. The log shows for every check whether it went over IPv4 or IPv6.

To check a site over both IPv4 and IPv6, open the monitor's Settings and select Also check over IPv6. That creates a second monitor with the same settings. It is a separate check on your interval, so it uses one more monitor slot.

Allow the IP addresses, not the user agent. Bot protection (such as Cloudflare Bot Fight Mode) blocks by behaviour as well, and a user agent is trivial to fake, so many firewalls ignore it.

Identify our checks with a header

Our IP addresses are shared by every PulseKeeper account. To let through only your checks, turn on the team token in Settings → Organization → Identify our checks. Every HTTP and API check of your team then sends:

X-PulseKeeper-Token: pkt_…

Allow requests that carry this header with your token, instead of (or in addition to) allowing our addresses. The token is secret: rotate it in the same place if it leaks, and update your firewall rule right after, because the old token stops being sent at once.

A single monitor can also send headers of its own: open the monitor, Settings → Request headers, and add one per line as Name: value.

Cloudflare

Cloudflare allows traffic with custom rules that use the Skip action.

With the team token (recommended):

  1. In the Cloudflare dashboard, open your site and go to Security rules.
  2. Select Create rule → Custom rules and give it a name, e.g. PulseKeeper.
  3. Select Edit expression and enter, with your token:
    any(http.request.headers["x-pulsekeeper-token"][*] eq "pkt_…")
    
  4. For the action choose Skip, and tick what to skip: all remaining custom rules, rate limiting rules, managed rules and Super Bot Fight Mode.
  5. Deploy the rule and move it to the top of the list, so it runs before the rules it skips.

With our IP addresses:

  1. Create an IP list: account Settings → Configurations → Lists → Create new list, content type IP address, name it e.g. pulsekeeper.
  2. Add the addresses from https://pulsekeeper.io/ips. The plain-text list is one address per line, so you can save it and use Upload CSV.
  3. Create a custom rule as above, with the expression ip.src in $pulsekeeper and the action Skip.

Cloudflare cannot fetch a list from a URL by itself. The addresses change only when we add a location; to keep the list in sync automatically, update it from https://pulsekeeper.io/ips.json with the Cloudflare Lists API.

The next check after the rule is deployed should come back green. There is nothing to reset on our side.

Bot Fight Mode (on the Free plan) cannot be skipped by any rule. If it is on, it will keep blocking our checks. Turn it off in Security → Settings, or use a plan with Super Bot Fight Mode, which the Skip action can exempt.

Sucuri, Imperva and Akamai

All three can exempt IP addresses from their protection. Look for the allowlist (sometimes whitelist) of IP addresses in the firewall or security settings of your site, add every address from the list above, and save. In Akamai this is usually a network list that you allow in your security configuration.

Your own server firewall

If you run ufw, iptables, a cloud firewall or an allowlist in nginx, allow the same addresses on the port you monitor (443 for HTTPS, or the port of a TCP monitor). A TCP monitor only opens a connection. See monitor types.