Bug: Updating IP Block Expiry time

arcrob

Bronze Partner
Basic Certified
Joined
Jan 13, 2022
Messages
22
Reaction score
12
Version: Version 20.0 Update 4 (Build 487 Release)
DO Hosted by me using their Marketplace image


Error when I try and update the expiry date of a IP Block. Work around is to remove the block and add it again with a later date.
IP Address already blacklisted

Replicate this by going to IP block list, select and Edit, override date and press OK.

Tested on a v18 and it functions as I would expect, allowing me to update the expiry date.

I do not have a vm running the alpha version at the min, but I do not see a fix in the changelog so may still be a current bug on that version.

Thanks
Rob
 
Hi this is not a bug, blacklisted IPs by the anti-hacking module will be blacklisted by the Blacklist time interval that by default it is 86400 seconds (24hs), you may set a longer time than that, lets say 31536000 (a Year).

In that way you don't have to edit the expiration date for those IPs blacklisted, they will stay there for a longer time.

On the other hand, if you manually add an IP as DENY then those IPs that were NOT added by the anti-hacking module you can edit the expiration date.

Have a good day!
 
Hi, Thanks Alejando.
That makes sense however it does allow you to override it in v18 so I presume just better error messaging is required if this is by design in v20.

Thanks
Rob
 
Hi,

We have our blacklist timeout set to 31104000 seconds (1 year). However, when I look at the blacklist for an IP address which I received an email about yesterday, that IP is not there. When I review my event log, I see the IP address was blacklisted, but not for the amount of time that is specified in the anti-hacking module. It seems to be random - 201s, 401s, 7601s, etc. Am I doing something incorrectly with V20? V18 blacklisted IPs used to block for the 1 year period and I just checked a few to verify.

Thanks for any assistance.
 
Hi,

We have our blacklist timeout set to 31104000 seconds (1 year). However, when I look at the blacklist for an IP address which I received an email about yesterday, that IP is not there. When I review my event log, I see the IP address was blacklisted, but not for the amount of time that is specified in the anti-hacking module. It seems to be random - 201s, 401s, 7601s, etc. Am I doing something incorrectly with V20? V18 blacklisted IPs used to block for the 1 year period and I just checked a few to verify.

Thanks for any assistance.
Hi, the anti-hacking module will block an IP for the Blacklist time interval when it meets the following criteria:
  • Failed Challenge Requests (407)
  • Security Barrier (Red)
  • Failed Authentication Protection (these are sip failed authentication)
Security Amber when reached it will block for 5 seconds, failed authentication in the webclient will be blocked for 900 seconds.

Now those random you said, do you receive any email notification? what information do you see in the event log? do you use any live chat?
 
Hi,

For the random time intervals, I do not receive an email notification. But do receive email notifications for other blacklist events. In the event logs, I see the following:

Level - Warning
Event ID - 12292
Date/Time

Details - The IP xxx.xxx.xxx.xxx has been blacklisted for 401 sec. Reason: requests rate is too high!

Several of these entries exist, time intervals anywhere from 201 - 7601 seconds.

No live chat configured here.

Thanks for the reply - if it would be better to take this offline to a support case, let me know and I can get one opened up.


Hi, the anti-hacking module will block an IP for the Blacklist time interval when it meets the following criteria:
  • Failed Challenge Requests (407)
  • Security Barrier (Red)
  • Failed Authentication Protection (these are sip failed authentication)
Security Amber when reached it will block for 5 seconds, failed authentication in the webclient will be blocked for 900 seconds.

Now those random you said, do you receive any email notification? what information do you see in the event log? do you use any live chat?
 
Hi this is not a bug, blacklisted IPs by the anti-hacking module will be blacklisted by the Blacklist time interval that by default it is 86400 seconds (24hs), you may set a longer time than that, lets say 31536000 (a Year).

In that way you don't have to edit the expiration date for those IPs blacklisted, they will stay there for a longer time.
I understand this is not technically "a bug", but to me that's certainly an incorrect functionality. I don't understand the purpose of preventing admins to edit the expiration date to whatever they'd like - personally I used to simply switch the 0 for a 1 in the year, making the ban effective for 100 years. Having to delete and recreate each deny entry to achieve this same purpose, is very annoying and time consuming - especially that they often come in batches, with several IPs being blacklisted within minutes.

Unless there's an incredibly good reason I'm missing, please consider removing this useless preventing-of-updating-the-expiry-time functionality.

(in a slightly different line of thought, the search functionality in the IP blacklist used to search on more fields than just IP... that way I could search for, say, "2024" and update all the results to be effective until "2124". Version 20 won't search within expiry dates like v18 used to. This forces me to search by IPs one by one, copy/pasting from the email notifications I received...

I can create a new post on that topic if you prefer)
 
Having to delete and recreate each deny entry to achieve this same purpose, is very annoying and time consuming - especially that they often come in batches, with several IPs being blacklisted within minutes.
Quick update: I deleted an entry created by the anti-hacking module in order to recreate it with a 100-year ban time, and it still tells me the IP already exists. Searching on the IP doesn't yield any result, as expected, but re-adding it won't work. Tried refreshing the page and even closed the tab in Chrome, to try and clear an eventual cache, but no luck.
 
Quick update: I deleted an entry created by the anti-hacking module in order to recreate it with a 100-year ban time, and it still tells me the IP already exists. Searching on the IP doesn't yield any result, as expected, but re-adding it won't work. Tried refreshing the page and even closed the tab in Chrome, to try and clear an eventual cache, but no luck.
If this is not in your list it means it has made it into our global IP blacklist. This is internal within the database and is not visible, and is permanent. So you dont need to worry about it any more.
 
  • Like
Reactions: EbenisterieNorclair

Latest Posts

Forum statistics

Threads
111,962
Messages
589,993
Members
164,867
Latest member
swegner