Skip to content

Brute Force Protection

DirectiveSyntaxDefault
LSBruteForceProtectionOn|OffOff
LSBruteForceAllowedAttemptsN10
LSBruteForceWindowseconds300
LSBruteForceActionblock|throttle|logblock
LSBruteForceThrottleDurationmilliseconds5000
LSBruteForceXForwardedForOn|OffOff
LSBruteForceTrustedProxyIP/CIDR [IP/CIDR ...](none)
LSBruteForceWhitelistIP/CIDR [IP/CIDR ...](none)
LSBruteForceProtectPath/path(none)
LSBruteForceProtection On
LSBruteForceAllowedAttempts 5
LSBruteForceWindow 600
LSBruteForceAction throttle
LSBruteForceThrottleDuration 10000
LSBruteForceXForwardedFor On
LSBruteForceTrustedProxy 10.0.0.0/8
LSBruteForceWhitelist 192.168.1.0/24 10.0.0.0/8
LSBruteForceProtectPath /wp-login.php

This throttles login attempts to 5 per 10 minutes, with a 10-second delay between throttled requests. Requests from the whitelisted subnets are exempt. Because LSBruteForceTrustedProxy is set, X-Forwarded-For is trusted only when the request arrives via 10.0.0.0/8.