Documentation

IP blocking

Three sightings in thirty minutes, one firewall rule, gone in 24 hours.

When an address is blocked

  • The agent reports authentication attempts with their source; the platform counts sightings per address.
  • An address seen attacking three times within thirty minutes becomes a block proposal.
  • On a server set to Automatic the block runs at the agent's next check-in, so usually within a minute or two. In Awaiting Approval it waits for you.

How

Through the tool the server already runs: fail2ban, CrowdSec, CSF, firewalld or iptables. SecAI installs no firewall. The rule is visible in that tool and the block is listed in the dashboard with its evidence. On a server managed with ufw the block is an iptables rule beside ufw's own, so it shows in "iptables -S" rather than in "ufw status".

Safety

  • Your own address and any address you mark as trusted are never blocked.
  • CDN edges in front of a proxied site are protected, so a site cannot be blocked by its own traffic.
  • Every automatic block expires after 24 hours.
  • The "Let me in" link in an alert lifts a block that caught you; unblocking never needs approval and works while automation is paused.

What it does not do

A distributed attack spread across many addresses does not trip a per-address threshold; the flood detector and an upstream provider address that shape. Blocks are not shared between customers.

Reviewed against the implementation on 2026-09-20. Something wrong? Tell us.

Trust Center