Banning an IP Address that Uses an Invalid Account

EFT Server can add an IP address to the Site’s IP ban list when a specified number of invalid login attempts occur over a specified period when a non-existing username was supplied. The offending IP address is added to the Site's IP address ban list. (The Site's IP address ban list can be viewed and managed on the Site's Connections tab.)

To automatically ban an IP address after a number of invalid login attempts

  1. In the administration interface, connect to EFT Server and click the Server tab.

  2. In the left pane, click the Site.

  3. In the right pane, click the Security tab.

  4. In the Password Security area, next to Invalid login options, click Configure. The Login Security Options dialog box appears.

    db_loginsecurityoptions_site64.png

  5. Select the Ban IP address check box, then specify the number of invalid login attempts and number of minutes during which to count the invalid logins.

  6. Click OK to save the changes and close the dialog box.

  7. Click Apply to save the changes on EFT Server.

The settings above cause the IP address to be added to the ban list on the 6th attempt (n+1). The values are the maximum failures ALLOWED before the IP address is banned. After the 6th login failure, the IP address would be banned.

Related Topics