> ## Documentation Index
> Fetch the complete documentation index at: https://docs.qa.tech/llms.txt
> Use this file to discover all available pages before exploring further.

# Environment access

> Reach a site the agent cannot load: identify the bot, allowlist IPs, or open a private network.

If a test cannot load the environment, match the symptom to a fix. Each row is a different blocker.

| Symptom                                                                               | Solution                                                         | Guide                                                                   |
| :------------------------------------------------------------------------------------ | :--------------------------------------------------------------- | :---------------------------------------------------------------------- |
| Logs or a WAF need to recognize QA.tech traffic                                       | Identify the bot by its User-Agent suffix                        | [QA.tech Bot](/bot)                                                     |
| A firewall, CDN, or CAPTCHA blocks the test by IP                                     | Allowlist the outbound IPs                                       | [IP Access](/configuration/ip-access-control)                           |
| Vercel Firewall returns a block before the app loads                                  | Bypass remaining rules when the User-Agent contains `QATechBot`  | [Vercel Firewall](/configuration/vercel-firewall)                       |
| A Vercel preview is behind deployment protection or trusted IPs                       | Send the Protection Bypass for Automation secret                 | [Vercel Preview](/configuration/vercel-preview-protection)              |
| Cloudflare returns 403, 1020, or a challenge page, or a Turnstile widget stops a form | Allow the bot at the edge, or change how the app loads Turnstile | [Cloudflare WAF and Turnstile](/configuration/cloudflare-waf-turnstile) |
| The app is on a private network or behind a jump host                                 | Route the browser through an SSH tunnel                          | [SSH Tunnel](/configuration/ssh-tunnel)                                 |
| The app is only on your machine                                                       | Expose local ports with `qatech tunnel`                          | [`qatech tunnel`](/cli/commands/tunnel)                                 |

<CardGroup cols={2}>
  <Card title="QA.tech Bot" icon="robot" href="/bot">
    User-Agent suffix `QATechBot/1.0` for logs and WAF rules.
  </Card>

  <Card title="IP Access" icon="globe" href="/configuration/ip-access-control">
    Allowlist the current outbound IPs from Settings → Network.
  </Card>

  <Card title="Vercel Firewall" icon="shield" href="/configuration/vercel-firewall">
    Custom rule: User-Agent contains `QATechBot`, then Bypass.
  </Card>

  <Card title="Vercel Preview" icon="shield-check" href="/configuration/vercel-preview-protection">
    Protection Bypass for Automation on a protected preview URL.
  </Card>

  <Card title="Cloudflare" icon="cloud" href="/configuration/cloudflare-waf-turnstile">
    Edge WAF and in-app Turnstile are different fixes.
  </Card>

  <Card title="SSH Tunnel" icon="shield-keyhole" href="/configuration/ssh-tunnel">
    SOCKS proxy through your jump host for private apps.
  </Card>

  <Card title="Localhost" icon="link" href="/cli/commands/tunnel">
    `qatech tunnel` exposes a dev server to the agent.
  </Card>
</CardGroup>
