Since the dawn of the World Wide Web, we've seen an abundance of innovative and barrier-breaking ways for people to connect and conduct business across national boundaries, time zones and cultures. The Internet however is not a utopia; there are negative aspects to the online world with varying degrees of maliciousness and criminality, like spammers, hackers, electronic data thieves and online con artists. So what can online merchants do to protect themselves?
Volusion provides a comprehensively secure e-commerce platform to our customers. The danger of having Volusion's security compromised is minimal. However, sometimes the issue is less about security and more about events that while not necessarily compromising security can negatively impact your business
Fortunately, Volusion come equipped with the IP Firewall. The IP Firewall allows you to restrict access to your Volusion store based on the IP address of incoming visitors.
An IP address is the unique network address assigned to every computer on the Internet. Blocking a specific IP address or range of addresses from being able to access your site is one of the greatest forms of control you can apply to a threat to your Volusion store. Here is how to use this tool to protect your business.
Restricting Users Based on Declined Orders
Sadly, one of the major problems with any online, e-commerce system is credit fraud. With the speed modern e-commerce solutions offer, it's now even faster for customers to purchase online. It's also even faster for criminals to enact credit fraud. One major issue in this context is the problem with credit thieves using an e-commerce store to "phish" (external link) for valid credit card numbers.
A credit thief will go to an online store and begin generating orders using different series of stolen credit information. Once the thief makes a successful order with one of the stolen account numbers in their possession, they know they have possession of a usable account number. This is of course bad news for the legitimate account holder but also bad for merchants in that they will have a large number of bogus, declined transactions piling up in their order table due to this type of activity.
Unfortunately, due to the nature of the Internet, there is no way to fully prevent this phenomenon. However there is a way to make your store undesirable as a test bed for credit thieves to use. Here's how:
- Log into the Admin Page, click on the Settings > IP Firewall.

- Click the Settings button.

- Enter a numerical value in the Max Orders Per Day Per IP field.

- Click Save.
Once set, this field will determine the maximum number of orders that may be processed for any one IP address in any 24 hour period.
When configured properly, this setting should not impact legitimate customers. It should, however, prevent credit thieves and the automated web software they employ from generating a large number of orders - a factor that will prevent thieves from effectively phishing for valid, active credit card accounts. By default, this setting is active and set to allow a maximum of 20 orders per day, per IP address. You may want to set this number as low as 5 or 10 or as they see fit.
Blocking IP Addresses
The most comprehensive way to block a particular visitor (or even whole region) from entering their online store is creating a rule for that user or region's IP address or IP address range. Again, this can be done in Volusion's IP Firewall tool.
- First, users must determine the IP or range of IP addresses to be blocked from entering their storefront (this will be described in detail below).
Once the IP address or range is determined, users can follow the above steps to log into the IP Firewall tool within the Admin Page.
- Log into the Admin Page, click on the Settings > IP Firewall.

- Click the Add button to create a new IP rule.

- If blocking a single IP address, enter this in the IP Range Begin field.
- If blocking an IP range, enter the first IP address in the range in the IP Range Begin field and the last IP in the IP Range End field.
- From the Allow Or Block drop-down menu, select Block.

- Click Save.
- Return to the Update Security Rules page and click the Settings button.
- Ensure that Enable IP Address Security Rules On Frontend is checked. Enabling this setting activates any and all IP rules that have been configured for the Volusion store storefront.

- Click Save to make the above settings active.
That's it, your IP rule is now set! Any computer based in the IP or within the IP range listed in any IP rule to block will be denied access to the Volusion storefront. You can repeat this process to create additional IP rules.
Finding IP Addresses
So you now know how to protect themselves by blocking threats to your online business via IP addresses - but how do you obtain those IP addresses in the first place? The easiest way to discover the IP address of a "troublesome" customer is through the order details page.
- Log into your Admin Page and, click on the Orders > Process Orders.

- Click the order ID of an order believed or confirmed to be suspect. Within the order details page for the order, examine the portion of the order details that contains the customer information.

You should see text similar to "This order was placed via ONLINE via IP Address 123.45.678.9". The string of numbers at the end of this block of text is the IP address of the system the order was generated from. The IP address in the block of text is a hypertext link and if you click it, you will be redirected to whois.domaintools.com page for this IP address.
Whois.domaintools.com provides a wealth of information regarding the IP address in question such as which ISP service generated the address, its physical location in the world and more.
You can further use this information to determine other possible IP addresses they may need to set IP rules for.
For example: A merchant may notice they have received a large number of fraudulent orders from IP addresses based in Angola. Using information provided through a whois look-up, the merchant can then determine the IP range for that entire geographic region and thus, create an IP rule for it.
Summary
Though the Internet may sometimes be a scary place, Volusion provides these tools to help merchants protect their online business. Volusion's hosting plan already provides comprehensive security and the IP Firewall settings within the Volusion Admin Page augment that security to help merchants sell online with piece of mind.