Understanding 403 errors and the Web Application Firewall (WAF)
Security first
The infrastructure that hosts the Membes AMS is built and managed with a “Security First” approach. Because Membes AMS handles important processes and sensitive data, we use multiple layers of protection, strict security protocols, and real-time monitoring to guard against the growing number of online threats.
What is a 403 error?
From time to time, this strong security posture can lead to a false positive, meaning the system may mistakenly identify a legitimate user as a potential threat. When that happens, access to all or parts of your Membes hosted resources is temporarily blocked. For the user, this will appear as a “403 error.”
For troubleshooting a 403 error, see below section “How to Resolve Blocked Access“.
What is a Web Application Firewall?
A Web Application Firewall (WAF) is a key part of the Membes AMS security infrastructure. It acts as a protective barrier between the internet and your website, filtering and monitoring traffic to stop malicious activity before it reaches the Membes platform.
Membes AMS uses an industry-standard AWS (Amazon Web Services) WAF, which provides enterprise-grade protection. This same technology is trusted globally by leading financial institutions, government agencies, and enterprise-level organisations.
The AWS WAF continuously analyses all incoming traffic to your site, identifying and blocking anything that could pose a security risk, such as:
Suspicious or repeated login attempts
Automated bots and data scraping
Injection or cross-site scripting (XSS) attacks
Unusual traffic patterns that may indicate a denial-of-service (DoS) or brute-force attempt
This ensures that your members’ data and your website are protected 24/7 from known and emerging online threats.
Why Some Users Might Experience Access Issues
In rare cases, legitimate users may encounter a “blocked” or “forbidden” message when trying to access your Membes website or administration area.
This usually occurs when the AWS WAF temporarily restricts access as part of its normal protective behaviour.
Some common reasons include:
Multiple failed login attempts in a short time frame
Use of a VPN, public connection such as hotel or cafe, or shared corporate network where the public IP address has been flagged for suspicious activity
Browser extensions or security software that alter traffic patterns
Submitting forms containing special characters or code-like input that may be interpreted as unsafe
These measures are designed to protect all Membes customers and their members from potential online threats.
How to Resolve Blocked Access
If a user reports that they are being blocked:
Ask them to clear their browser cache and cookies and try again.
If they are using a VPN or corporate network, ask them to disconnect the VPN or switch to a standard internet connection.
If the issue continues, they can wait approximately 30 minutes before trying again. Temporary security blocks often expire automatically.
If the problem persists, an administrator with Help Desk access can submit a support ticket through the Membes Support Hub.
When submitting a ticket, please include:
The affected user’s IP address
A short description of what they were doing (e.g. logging in, submitting a form)
The approximate time the block occurred
This information will help the Membes Support Team investigate and whitelist the legitimate traffic if appropriate.