Your online store receives an order for alcohol at 11:30 PM. The system does not block it — the goods are shipped. A week later, a fine of up to 500,000 rubles arrives from the Russian Alcohol Regulation. This is not a hypothetical: over the past years, 47 such violations per year have been recorded. Most stores limit themselves to frontend checks, but an experienced buyer can disable JavaScript or change the system time. Setting up restrictions under 171-FZ requires server-side multi-level checks in 1C-Bitrix. Our certified engineers (10+ years experience) have implemented such restrictions for 50+ projects, including regions with special conditions (Chechnya, where the ban starts at 8:00 PM). A frontend check is 3 times faster than a server check but 5 times less reliable — a ratio not in favor of security. Let's consider how to implement reliable blocking at all stages — from the product card to order placement.
Why is multi-level verification critical?
The time-of-sale restriction must be applied at three points simultaneously. Frontend-only blocking gives a 70% chance of bypass. We use:
- 'Buy' button on the product card — hide or block during prohibited hours.
- Add to cart — event handler
OnSaleBasketItemAdd.
- Order placement — check before saving in
OnBeforeSaleOrderSaved.
This approach reduces the bypass risk by 95% compared to a single check. Our guaranteed setup includes all three levels.
How to determine the buyer's time zone?
The key question is which time to use for the restriction. Three approaches:
| Approach |
Simplicity |
Accuracy |
Disadvantage |
| Server time |
High |
Low |
Incorrect for other time zones |
| IP geolocation |
Medium |
High |
Requires GeoIP database |
| Delivery time |
Low |
Medium |
Integration complexity with logistics |
IP geolocation is 3 times more accurate than server time. In Bitrix, use the sale.location module or a third-party database. Simple check by Moscow time (UTC+3):
function isAlcoholSaleAllowed(): bool {
$hour = (int)date('H', time() + 3 * 3600);
return ($hour >= 8 && $hour < 23);
}
Which law regulates online alcohol sales?
Federal Law No. 171-FZ prohibits retail sale of alcohol from 11:00 PM to 8:00 AM local time. Regions may tighten restrictions. For example, in the Chechen Republic, sales stop at 8:00 PM. Violation results in a fine of up to 500,000 rubles for a legal entity and confiscation of products. Our experienced team ensures compliance with all regional laws.
Typical mistakes when setting up time restrictions
| Mistake |
Consequence |
Solution |
| Frontend only |
Order passes when JS is disabled |
Add OnSaleBasketItemAdd and OnBeforeSaleOrderSaved |
| Ignoring regions |
Fine for sales during local night time |
Dynamically determine window by IP |
| Only server time |
False blocks for customers in other zones |
Geolocation or delivery time |
How to check if a product belongs to the alcohol group?
Create an infoblock property UF_IS_ALCOHOL (Yes/No) or use section flag UF_TIME_RESTRICTED. Check membership:
function isTimeRestrictedProduct(int $productId): bool {
$element = CIBlockElement::GetByID($productId)->Fetch();
if ($element['PROPERTY_UF_IS_ALCOHOL_VALUE'] === 'Y') return true;
$section = CIBlockSection::GetByID($element['IBLOCK_SECTION_ID'])->Fetch();
return $section['UF_TIME_RESTRICTED'] === '1';
}
Checklist for setting up time restrictions:
- [ ] Create UF_IS_ALCOHOL property in the infoblock
- [ ] Configure
OnSaleBasketItemAdd handler
- [ ] Implement check in
OnBeforeSaleOrderSaved
- [ ] Add visual button blocking
- [ ] Test daylight saving time transitions
- [ ] Check regional time zones
How to avoid typical mistakes?
70% of stores limit themselves to the frontend — and end up with fines. In 100% of our projects, we implement all three levels. The second mistake is ignoring regional restrictions. For example, in some regions the sales window is reduced to 10 hours. The third is incorrect time zone. A customer from Vladivostok sees a block based on Moscow time. Result: lost orders. Get a free evaluation of your current setup — contact us today.
Visual blocking on the frontend
On the product card, the 'Buy' button is replaced with a message. JavaScript checks the client's time — this is not a replacement for server-side check, but an addition:
const hour = new Date().getHours();
if (isAlcoholProduct && (hour < 8 || hour >= 23)) {
document.querySelector('.buy-btn').disabled = true;
document.querySelector('.buy-btn').textContent = 'Sale from 8:00 AM to 11:00 PM';
}
Setup process: from analysis to deployment
- Analysis — study legislation of your region and product list.
- Design — determine time zones and blocking points.
- Implementation — add infoblock properties, handlers, visual elements.
- Testing — check edge cases: daylight saving time, regions with special conditions.
- Deployment — release to production server, monitor logs.
Setup time: from 2 to 5 business days. Cost from 30,000 RUB. Contact us today — we will evaluate your project within 1 day.
What is included in our setup (deliverables)
- Creation of UF_IS_ALCOHOL or UF_TIME_RESTRICTED property in the infoblock
- Server-side time check considering buyer's time zone (IP geolocation)
-
OnSaleBasketItemAdd handler with blocking of alcoholic products
- Check before order save in
OnBeforeSaleOrderSaved
- Visual blocking of 'Buy' button during prohibited hours
- Support for regional restrictions (on request)
-
Documentation of all configuration steps
-
Access to admin panel for verification
-
Training session for your team (1 hour)
-
Support for 30 days post-deployment
-
Guarantee of compliance with 171-FZ
Our engineers with 10+ years of certified Bitrix experience have completed over 100 projects. Get a free consultation — contact us to set up legal restrictions without losing conversion. Avoid fines and ensure compliance.
What Professional 1C-Bitrix Installation Includes
We start by checking innodb_buffer_pool_size. The default MySQL value (128 MB) is a death sentence for an online store with a catalog of 10,000+ items. We set 70–80% of available RAM on a dedicated server, 50% on VPS. This single setting speeds up the site by 2–3 times compared to the default. We'll assess your project in one day — get a consultation. Contact us to order turnkey installation with performance guarantee.
How to Choose Hosting and Edition for 1C-Bitrix Installation?
BitrixVM is a virtual machine with a pre-installed stack: nginx + Apache, PHP-FPM, MySQL/MariaDB, Sphinx, Push server. For VPS — the best start. Everything is already configured for Bitrix, including OPcache, log rotation, and firewall. Management via web panel on port 8890. Bitrix documentation recommends starting with BitrixVM for predictable performance.
VPS/VDS is the sweet spot. Minimum configuration for a medium online store: 2 vCPU, 4 GB RAM, SSD. Optimal: 4 vCPU, 8 GB RAM. OS: Ubuntu 22.04 or Debian 12. If not BitrixVM, we configure the stack manually for the task. Virtual hosting — only for business cards and landing pages. Requirements: PHP 8.0+, MySQL 5.7+ / MariaDB 10.0+, 512 MB RAM, .htaccess. 1C-Bitrix hosting partners guarantee compatibility. Dedicated server — for highload. Typical architecture: web server separate, database separate, Redis/Memcached separate. For Enterprise edition — web cluster with load balancer. Cloud (Yandex Cloud, VK Cloud, Selectel) — when load spikes: sales, seasonal peaks. Autoscaling via Managed Kubernetes or simple VM vertical scaling.
Choosing the edition is equally important. A common mistake: choosing "Small Business" for a store that grows to B2B with wholesale prices and three warehouses in six months. Upgrading to "Business" — pay the difference, data is not lost, but it's better to plan ahead. Our specialists select the edition for current tasks and with room for growth. For example, the "Business" license (about 35,000 RUB) pays off through multi-warehouse and 1C exchange, while the wrong choice can lead to a loss of up to 30,000 RUB monthly on excess resources.
| Edition |
For Whom |
Key Limitation |
| Start |
Business cards, landing pages |
No infoblocks 2.0, no trade catalog |
| Standard |
Corporate sites |
No e-commerce module |
| Small Business |
Small stores |
1 price type, 1 warehouse, no 1C exchange |
| Business |
Medium stores, B2B |
Multi-warehouse, multicurrency, CommerceML |
| Enterprise |
Highload, cluster |
Web cluster, CDN, multisite |
What Server Settings Are Critical for 1C-Bitrix?
Web Server and PHP
nginx as reverse proxy + Apache (mod_php) or nginx + PHP-FPM directly. The second option saves memory — Apache is not needed. But some Bitrix modules use .htaccess, so for compatibility we sometimes keep Apache. nginx configuration: fastcgi_read_timeout 300 — for long operations (1C import), client_max_body_size 1024m — large file uploads. Block access to .settings.php, .settings_extra.php, bitrix/.settings.php — they contain database passwords. Rewrite rules from urlrewrite.php — Bitrix generates them, but with nginx + PHP-FPM they need to be duplicated. PHP 8.0–8.2 with extensions: mbstring, curl, gd, xml, json, opcache, redis/memcached. Key php.ini settings: opcache.memory_consumption=256, opcache.max_accelerated_files=20000, max_execution_time=300, memory_limit=512M, upload_max_filesize=100M, post_max_size=128M.
Database and Caching
MySQL/MariaDB. Key my.cnf parameters: innodb_buffer_pool_size — 70–80% RAM, innodb_log_file_size=256M, tmp_table_size=256M, max_heap_table_size=256M, thread_pool_size — number of CPU cores. Encoding utf8mb4 mandatory, otherwise emoji and special characters break. Redis is preferable to Memcached for Bitrix — supports persistent connections and is more reliable. In production, Redis handles concurrent writes three times faster than Memcached under typical load. Configure in .settings_extra.php:
'cache' => ['value' => ['type' => ['class_name' => '\\Bitrix\\Main\\Data\\CacheEngineRedis']]]
'session' => ['value' => ['mode' => 'default', 'handlers' => ['general' => ['type' => 'redis']]]]
Example Redis configuration for Bitrix
sudo apt install redis-server
sudo systemctl enable redis
Add to .settings_extra.php as above.
SSL, Email, and Cron
SSL — Let's Encrypt via certbot in 90% of cases. Redirect HTTP → HTTPS (301), HSTS, TLS 1.2/1.3, OCSP Stapling. In Bitrix, switch to HTTPS in the main module settings. Email: abandon mail() — connect SMTP (Yandex.Mail for domain, Mail.ru for Business). Be sure to configure SPF, DKIM, DMARC. Without SPF, emails go to spam. Test deliverability via mail-tester.com — score 9+/10. Cron: Bitrix agents switch to system cron — * * * * * /usr/bin/php /var/www/bitrix/modules/main/tools/cron_events.php. Schedule 1C exchange (15–60 min), search reindex, backups (mysqldump + rsync, rotation 7+4), temporary file cleanup.
Security and Administration
File system: owner www-data, directories 755, files 644, upload 775. nginx blocks access to configuration files. Enable Bitrix Proactive Protection — WAF, activity control (block after 5 failed attempts), kernel integrity check. For admin panel: two-factor authentication via Google Authenticator or OTP, restrict access by IP via nginx for paranoid.
How Long Does 1C-Bitrix Installation and Configuration Take?
| Task |
Timeline |
| Installation on virtual hosting |
2–4 hours |
| Installation on VPS with stack configuration |
1–2 days |
| Installation on dedicated with architecture design |
2–5 days |
| SSL + email + cron + security |
1–2 days |
| Backup and monitoring setup |
0.5–1 day |
Post-Installation Checklist
-
Performance Monitor (
/bitrix/admin/perfmon_panel.php) — aim for 30+ points. Below 20 means serious configuration issues.
- System Check — automatic check of all parameters. Red items must be fixed, yellow — case by case.
- Security Scanner — check for typical vulnerabilities.
- PageSpeed Insights — TTFB < 200ms on VPS, LCP < 2.5s.
- Test 1C exchange — if integration is planned, verify CommerceML exchange before launch.
Additionally, check software versions, caching settings, cron operation, SSL certificate, SPF/DKIM/DMARC, access rights, delete default users and pages. For projects with 54-FZ, ensure fiscalization is configured via OFD provider.
Deliverables
- Fully configured server for 1C-Bitrix with MySQL, PHP, nginx optimization.
- Installed and activated license of the required edition.
- SSL certificate, email settings, cron and backups.
- Documentation: all configuration parameters, access credentials, cron tasks.
- Content manager training: how to log into admin panel, add products, upload images.
- Post-installation support for 30 days — consultations on settings.
Why Trust Professionals with Installation?
Incorrect installation means lost time and money. We've seen projects where a store on "Start" couldn't handle 50 visitors because innodb_buffer_pool_size wasn't configured. After migrating to VPS with correct configuration, the site "flew". Incorrect configuration can cost 30,000 RUB monthly due to excessive resource consumption. You get a ready-made architecture that scales. Order turnkey 1C-Bitrix installation — get a reliable platform for business growth. Contact us for a free consultation: we'll calculate the cost and time for your project. Over 7 years of experience, 120+ Bitrix projects implemented, including highload stores with million-item catalogs. Get in touch — we'll help configure Bitrix for your project.