Allow Lemwatch checks through your firewall, WAF, or rate limiter using our published IP ranges and User-Agent.
Quick answer
Copy the Lemwatch probe IP ranges and User-Agent from Settings → Monitoring → Probe IPs and add them to your firewall, WAF, and rate limiter allow-lists. This stops false "down" alerts caused by your own security tools.
What it fixes
403/429/503 responses to Lemwatch only
Sites that show "down" in Lemwatch but load fine in your browser
Intermittent alerts that clear seconds later
Bot-challenge pages returning HTML 200s instead of your real site
Where to find it in Lemwatch
Settings → Monitoring → Probe IPs. Copy the CIDR ranges and the Lemwatch/1.0 User-Agent string.
How to whitelist
Open Settings → Monitoring → Probe IPs and copy the ranges.
Add the IPs to your firewall or WAF allow-list (Cloudflare, AWS WAF, Sucuri, Wordfence, etc.).
Add the Lemwatch/1.0 User-Agent to any bot-management or rate-limiter rule.
If you use Fail2Ban or similar, add the IPs to ignoreip.
Run Check now on the affected site — the alert should clear within 60 seconds.
FAQ
Do the IPs change?
Rarely — we publish 7-day advance notice via the Changelog and email when they do.
Can I identify Lemwatch by User-Agent alone?
Yes, but IP + UA is safer since UA strings are trivially spoofed.