For Brute Force login attempts, Once the rule is triggered, does each subsequent attempt reset (extend) the time, or is the time length tied to the trigger event ?
Question asked by Curtis Kropar www.HawaiianHope.org - 6/21/2022 at 7:46 PM
Lets say I have a rule that says once brute force is detected, ban that IP for 30 days.
If on day 25 that IP attempts to login in again, it should show the connection rejected, but does the 30 days get reset again and it is now 30 days from that attempt, or in 5 days will it clear ?

Personally I would want it to extend another 30 days if they showed back up again.

echoDreamz Replied
I wish it worked liked that, or atleast an option to work like that. Once the timer starts, it doesn’t reset until the clock runs out and the IP triggers the detection once again. 

