Brute Force Protection – Not Blocking Failed Logins
-
I have Brute Force Protection enabled.
I have “Lock out after how many login failures” set to 5.
I have 3 specific usernames listed in “Immediately block the IP of users who try to sign in as these usernames”.
“Count failures over what time period” is set to 10 minutes.
“Amount of time a user is locked out” is set to 12 hours.
Even though all this seems to be setup, I still regularly see 8-10 attempted failed logins all within a few minutes of each other from the same IP address, and they remain unblocked.
I have seen one IP address blocked by Wordfence, but that was just one time and it has just now apparently been unblocked automatically (I assume expired).
I’m not even sure how they are getting to 8-9 attempts. I would expect it would block them at attempt #6.
- The topic ‘Brute Force Protection – Not Blocking Failed Logins’ is closed to new replies.