Brute Force Protection
Directives
Section titled “Directives”| Directive | Syntax | Default |
|---|---|---|
LSBruteForceProtection | On|Off | Off |
LSBruteForceAllowedAttempts | N | 10 |
LSBruteForceWindow | seconds | 300 |
LSBruteForceAction | block|throttle|log | block |
LSBruteForceThrottleDuration | milliseconds | 5000 |
LSBruteForceXForwardedFor | On|Off | Off |
LSBruteForceTrustedProxy | IP/CIDR [IP/CIDR ...] | (none) |
LSBruteForceWhitelist | IP/CIDR [IP/CIDR ...] | (none) |
LSBruteForceProtectPath | /path | (none) |
Example
Section titled “Example”Protect WordPress Login
Section titled “Protect WordPress Login”LSBruteForceProtection OnLSBruteForceAllowedAttempts 5LSBruteForceWindow 600LSBruteForceAction throttleLSBruteForceThrottleDuration 10000LSBruteForceXForwardedFor OnLSBruteForceTrustedProxy 10.0.0.0/8LSBruteForceWhitelist 192.168.1.0/24 10.0.0.0/8LSBruteForceProtectPath /wp-login.phpThis throttles login attempts to 5 per 10 minutes, with a 10-second delay between throttled requests. Requests from the whitelisted subnets are exempt. Because LSBruteForceTrustedProxy is set, X-Forwarded-For is trusted only when the request arrives via 10.0.0.0/8.