Article Background
Back to Knowledgebase

How to Set Up IP Whitelisting and Protected Directories in DirectAdmin

Web
Cubes Support
July 20, 2026

Restricting access to sensitive subdirectories on your website (such as /admin/, /wp-admin/, /staging/, or internal database tools) is one of the most effective ways to block hackers, automated bot scanners, and brute-force attacks.

DirectAdmin allows you to protect directories using Password Protection (HTTP Basic Authentication) or by configuring an IP Address Whitelist using .htaccess.

This guide will walk you through setting up both protection methods on your Cubes Hosting account.


Method 1: Password Protecting Directories in DirectAdmin (HTTP Basic Auth)

Password protecting a folder forces any web browser attempting to access that URL to enter a username and password before loading any files.

  1. Log in to your Cubes Hosting DirectAdmin Control Panel.
  2. Navigate to Account Manager > Password Protected Directories (or Directory Protection).
  3. Click Find Directory to Protect.
  4. Browse your file system and click Protect next to the folder you wish to lock down (e.g., public_html/admin/ or public_html/staging/).
  5. Configure the protection settings:
    • Protected Directory Prompt: Enter a label for the popup dialog (e.g., Restricted Admin Area).
    • Set Username & Password: Create an authorized user account for this folder.
  6. Check Protection Enabled and click Save.

Now, whenever anyone visits http://yourdomain.com/admin/, their browser will display an authentication popup requiring the password you set!


Method 2: IP Address Whitelisting via .htaccess

IP Whitelisting restricts folder access so that only specific IP addresses (such as your home or office internet connection) can view the files. All other IP addresses receive a 403 Forbidden error.

How to Create an IP Whitelist:

  1. Open your DirectAdmin File Manager.
  2. Navigate to the folder you want to restrict (e.g. /public_html/admin/ or /public_html/wp-admin/).
  3. Create or edit the .htaccess file inside that folder.
  4. Add the following Apache 2.4 IP restriction code:
# Restrict folder access to allowed IP addresses only
<RequireAll>
  # Allow your home or office IP address
  Require ip 203.0.113.50

  # Allow a secondary staff IP address or subnet
  Require ip 198.51.100.12
</RequireAll>
  1. Replace 203.0.113.50 with your actual public IP address (you can find your public IP by visiting google.com and searching "what is my IP").
  2. Save the .htaccess file.

Combining Password Protection + IP Whitelisting

For maximum security on critical admin portals, combine both methods:

  1. Add an IP Whitelist in .htaccess to block automated global bot networks.
  2. Enable DirectAdmin Password Protection so that even if someone gets on your network, they still require a password to enter.


Conclusion

Locking down sensitive website folders takes less than two minutes. Use Password Protected Directories in DirectAdmin or restrict access to your IP address via .htaccess to keep your admin panels safe!

Special Offer

Ready to Start Your Server?

Get 10% OFF your first month on any server with promo code CUBES10 at checkout!

24/7 Assistance

Need Help With Your Server?

Already a Cubes Hosting customer and couldn't find your answer? Our dedicated support team is available 24/7.