Skip to content

Settings

In the console: Settings › Security › Settings

When the server blocks an address by itself: after repeated wrong passwords, abuse or scanning.

Authentication failure ban

Rate

The maximum number of failed login attempts before the IP is banned.

Settings of their own: see Rate. Name in the API: authBanRate.

Duration

The duration of the ban for failed login attempts.

A length of time. Name in the API: authBanPeriod.

Abuse attempt ban

Rate

The maximum number of abuse attempts (relaying or failed RCPT TO attempts) before the IP is banned.

Settings of their own: see Rate. Name in the API: abuseBanRate.

Duration

The duration of the ban for abuse attempts.

A length of time. Name in the API: abuseBanPeriod.

Loitering ban

Rate

The maximum number of loitering disconnections before the IP is banned.

Settings of their own: see Rate. Name in the API: loiterBanRate.

Duration

The duration of the ban for loitering connections.

A length of time. Name in the API: loiterBanPeriod.

Port scanning ban

Rate

The maximum number of port scanning attempts before the IP is banned.

Settings of their own: see Rate. Name in the API: scanBanRate.

HTTP banned paths

The paths that will trigger an immediate ban if accessed. Each path should be a glob expression.

A list. Each one: text. Default: ../, .asp, .cgi, .php…. Name in the API: scanBanPaths.

Duration

The duration of the ban for port scanning attempts.

A length of time. Name in the API: scanBanPeriod.