Viewing 1 replies (of 1 total)
  • My opinion is that it isn’t worth the time to block specific IPs. They usually change. And if they’re hammering away at invalid usernames, they’re not going to make any headway.

    I bump up the login lockout time to 30 days and leave it alone. I don’t even bother with email alerts of failed logins.

Viewing 1 replies (of 1 total)

The topic ‘Blocking repeated malicious login attempts’ is closed to new replies.