Allowing Payment Gateway IP's in UAM

An application on our server is currently experiencing a DDoS attack, we’ve activated Under Attack Mode however it is blocking the callback from the payment processor’s IP to update the order status.

Can anyone advise on steps to allow the IP so the site can transact whilst in UAM?

Under Attack Mode is an 'easy button` to turn on managed challenge globally. You can use page rules and fiurewall rules to create a similar rule or set of rules with exclusions for IP addresses or endpoints you wish to exclude.

