Nginx Pro for DDoS Protection & Googlebot Access

via Freelancer ·

Budget / SalaryHourly project
TypeFreelance project
LocationRemote
Posted1 hour ago
URGENT] Nginx Expert Needed: Implement Googlebot Whitelisting & Smart Rate Limiting without Dropping Connections
​Job Type: Fixed-Price / Hourly (Urgent)
Category: Server Administration / DevOps / Nginx Security
​Project Overview:
We are experiencing DDoS attacks on our production server. Recently, strict Nginx blocking rules were applied to mitigate the attack, but this caused our Google Search Console (GSC) Server Connectivity failure rate to spike to 35%, drastically putting our organic rankings at risk.
​The immediate blocking rules were temporarily removed to restore crawling, but as a result, DDoS attacks have resumed.
​We need a seasoned Nginx / Systems Administrator to design and implement a robust, automated solution that protects our server from DDoS attacks while guaranteeing 100% uninterrupted access for official Google crawlers.
​Scope of Work & Requirements:
​Automated Googlebot IP Whitelisting / Dynamic Updating:
​Fetch and parse Google's official JSON IP ranges automatically via a custom cron script:
​Googlebot IPs: [https://developers.google.com/search/apis/ipranges/googlebot.json](https://developers.google.com/search/apis/ipranges/googlebot.json)
​Special Crawlers: [https://developers.google.com/search/apis/ipranges/special-crawlers.json](https://developers.google.com/search/apis/ipranges/special-crawlers.json)
​Automatically sync these IPs into the Nginx access control rules (or geo block/ipset) and safely reload Nginx.
​Alternately, implement verified Reverse DNS lookups (.googlebot.com / .google.com) alongside the CIDR range whitelisting for strict verification.
​Targeted Rate Limiting & Bot Protection:
​Do NOT apply blanket rate-limiting across the entire domain or drop connections at the network level for search bots.
​Apply strict rate limiting specifically to sensitive endpoints (e.g., POST requests on /login, /wp-login.php, API endpoints, registration forms).
​Ensure legitimate GET requests for search crawlers pass through without throttling or timeouts.
​Proper HTTP Status Handling (No Connection Drops):
​Ensure Nginx never abruptly drops TCP connections (drop, reset), hangs requests, or triggers connection timeouts.
​If a non-whitelisted IP hits a restricted or blocked path, Nginx must return a proper HTTP 403 Forbidden (or 429 Too Many Requests) header instead of closing the connection silently. This ensures Google Search Console does not log "Server Connectivity Failures".
​Testing, Log Verification, & Handover:
​Verify configuration using dry runs and log checks: grep -i "googlebot" /var/log/nginx/access.log and error.log.
​Test simulated Googlebot user-agents/IPs to ensure zero false positives.
​Provide brief documentation for the custom sync script and Nginx rules implemented.
​Required Skills:
​Advanced Nginx configuration (Rate Limiting, geo blocks, map directives, limit_req).
​Bash / Python Scripting (Cron jobs for dynamic JSON parsing & firewalls/Nginx reloads).
​Deep understanding of Googlebot Crawling Infrastructure & SEO technical health.
​Linux Server Security (iptables, fail2ban, ipset experience is a plus).
​To Apply:
​Please briefly outline your experience with Nginx rate-limiting strategies and dynamic IP whitelisting. Mention "NGINX-GOOGLEBOT" at the top of your proposal to show you have read the complete project description.
php python linux web security nginx devops bash firewall
Apply on Freelancer →

Project sourced from Freelancer.com. Applications happen directly on the original platform — we never collect your data.