Suspicious IP Throttling Reset Frequency

Overview

This article explains what happens after a user gets blocked from a non-allowlisted IP address and whether it resets at some point.

Applies To

  • Suspicious IP Throttling

Solution

After an IP hits the thresholds and is blocked, (assuming the default throttling rate is used of 100 per day, with a maximum of 100):

  • It takes ~15 minutes for the IP to become unblocked, and there will be 1 available attempt at that time. After ~30 minutes, there will be 2 attempts, etc.
  • It takes 24 hours to replenish all 100 attempts (because it replenishes at a rate of 100 attempts per day).

Note: If there are new failed login attempts during that time, they will be subtracted from the available attempts. For example, after 12 hours, there are 50 attempts available, but one failed login attempt will reset back to 49 attempts available.

Throttling rates and maximum attempts can be configured as per the documentation here: Configure throttling limits and rates