Geonode logo
Website blocks

How to Fix Cloudflare Error 1005 (ASN Banned)

Look up whose network was refused, then take the step that fits your role.

Updated

TL;DR

Error 1005 means the owner of a site behind Cloudflare banned the whole network (ASN) your IP address belongs to, so Cloudflare refuses every request from it with HTTP 403. If a VPN or proxy carried you there, reload without it; otherwise only the owner can lift the ban.

What error 1005 looks like

Cloudflare picks the format from your client's Accept header. Here example.com is the site and 64500, a number reserved for documentation, is your AS number.

WhereWhat you see
Browser, page headerError 1005 / Ray ID: a46ad6709ae3dd36 • 2026-10-07 06:27:01 UTC / Access denied
Browser, What happened? section...banned the autonomous system number (ASN) your IP address is in (64500) from accessing this website.
Browser tab titleAccess denied | example.com used Cloudflare to restrict access
Browser, page footerCloudflare Ray ID: a46ad6709ae3dd36 • Your IP: Click to reveal • Performance & security by Cloudflare
curl -i, default headersHTTP/2 403 / content-type: text/plain; charset=UTF-8 / error code: 1005
Script sending Accept: application/json and Accept-Encoding: gzip"title":"Error 1005: Access denied","status":403 / "detail":"The site owner has blocked the autonomous system number (ASN) associated with your IP address." / "error_name":"asn_banned","error_category":"access_denied","retryable":false

Why this happens

The site's owner turned away everyone on the network your connection comes from.

An ASN is the number of one operator's network, such as a home ISP or a cloud host. Cloudflare's blog offers ASN lists for handling cloud and ISP networks where bots may be hosted.

Diagnose your 1005 first

Start in the browser that showed 1005; the last two checks are for scripts on servers.

  • Open What is my IP in that browser; if the ISP shown is not yours, a VPN, proxy or work gateway probably got banned.

  • Look up the bracketed number on the 1005 page in RIPEstat; if the holder is your own ISP, every customer on that network is banned.

  • If a script on a server gets 1005, open the URL on your own computer; if it loads, the server's cloud network is banned.

  • Have the script log each 403's body, where Cloudflare puts the 1xxx code; if it reads 'error code: 1005', the ASN ban stopped it.

Solutions ranked by effectiveness

Start with the first card unless you run the site or a job on a server.

  1. Most common fix

    Turn off the VPN, then contact the owner

    Applies when a VPN, proxy or relay sits on your usual connection: if the page opens without it, that service's network was banned.

    1. Disconnect the VPN, reset the browser to no proxy and pause proxy extensions.

    2. If 1005 stays, screenshot the whole page so the AS number and Ray ID show.

    3. Email it to the site; a contact form on the same site is blocked too.

  2. Site owners

    Narrow the ASN rule behind the ban

    Applies when a visitor reports 1005: the AS number on their screenshot points to the IP Access rule that refused them.

    1. Filter Security > Analytics Events by ASN (13335, no prefix) to see what was stopped.

    2. Under Security rules, open IP access rules; ASNs there carry the prefix, as in AS13335.

    3. Delete the Block entry if the whole network should not be banned.

    4. Otherwise allow the visitor's IP if it is static; Allow takes precedence over Block.

  3. For developers

    Ask for access with your job's ASN

    Applies when a job on a server gets 1005. Stop the job, and if the site's terms allow such jobs, run this on that server and send the owner the IP and ASN it prints.

    import json, urllib.request
    
    def stat(call, resource=""):
        url = f"https://stat.ripe.net/data/{call}/data.json?resource={resource}"
        with urllib.request.urlopen(url, timeout=30) as r:
            return json.load(r)["data"]
    
    ip = stat("whats-my-ip")["ip"]
    for asn in stat("network-info", ip)["asns"]:
        print(ip, f"AS{asn}", stat("as-overview", f"AS{asn}")["holder"])

Stop the 1005 from coming back

One habit for automated jobs, and two for site owners who write ASN rules.

  1. Before a job's first run, send one request per site and drop sites that answer 1005.

  2. Before banning an ASN, check its holder; Cloudflare warns that a wrong ASN cuts off a large range of IPs.

  3. For a broad ASN rule, choose Managed Challenge over Block, so people on that network get a challenge instead.

Keep each owner's approval on recordAdd a note to any ISP IP naming the sites whose owners approved it.
Try ISP proxies

Related errors

Learn more

FAQ

It is Cloudflare's Access denied page for an autonomous system number (ASN) block: the site's owner refuses every request from one operator's network, such as your internet provider or a VPN company. It targets the network, not you personally.

Turn off any VPN or proxy and reload. If 1005 is still there on your usual connection, send the site's owner a screenshot with the Ray ID, since only the owner can remove the ban or allow your IP.

Only by bypassing the owner's decision, which Cloudflare's reply calls intentional, so another VPN server or a proxy is not a fix. Dropping a VPN whose network was the banned one is fine: it returns you to your own provider.

No. It is one owner's rule, set for their website or for all websites in their Cloudflare account, so sites run by other owners still load unless they banned your network too.

It lasts until the owner removes the ASN rule or allows your IP. Cloudflare's JSON reply for 1005 marks it retryable: false and owner_action_required: true, with no Retry-After header.

No. The rule matches the network your IP address belongs to, not anything your browser stores, so clearing cookies or cache or opening a private window changes nothing.

One IP an owner can allow

A Dedicated ISP IP serves only you, so an owner's Allow rule covers just you.