Two ways to allow or block addresses.
IP ACCESS RULES
A simple list: an address, a range, a country or a network, with an action.
Quick to add, limited in what they can match.
FIREWALL RULES
Expressions combining several conditions: path, method, user agent, country, address.
More capable, and they take a little more thought.
WHEN TO USE EACH
An access rule for a straightforward case: allow your office address, block a specific abusive address.
A firewall rule for anything conditional: challenge requests to the login path from outside Nigeria.
THE ORDER OF EVALUATION
Allow rules take precedence over blocks. An address you have explicitly allowed is not caught by a later blocking rule.
That is useful: allow your own address first, then apply restrictive rules without locking yourself out.
WHAT TO ADD FIRST
Your own address, allowed. Before you create anything restrictive.
Otherwise the first overly broad rule locks you out of your own site.
REVIEWING THEM
Annually. Rules added for a past problem remain and eventually block something you now depend on.