Platform-level DDoS block not cleared by System Bypass Rules or Pausing Mitigations

Projects: mozio-front-end-transfer-next and mozio-front-end-car-rental

Symptom: Requests are being blocked with x-vercel-mitigated: deny response headers. The traffic originates from a small set of nginx proxy IPs that forward requests from a sibling project.

What I’ve already tried:

  • Paused System Mitigations on the project

  • Added 5 System Bypass Rules covering all nginx proxy IPs

  • The working sibling project mozio-front-end-transfer has an identical firewall configuration and handles the same proxy traffic without issues

Timeline: This was working correctly on Friday. The block appeared after the weekend with no configuration changes on our side.

What I believe is happening: Based on similar reports in this forum, the block appears to be at the platform level - below where WAF bypass rules take effect. The bypass rules and paused mitigations don’t seem to be able to override it. A manual platform-side unblock appears to be required.

Ask: Can a Vercel team member manually clear the platform-level block on this project and/or the specific proxy IPs? Happy to share the full IP list via DM. I also have an open support ticket but haven’t received a response in 6+ hours - this is blocking production traffic.