I notice that Auth0 has brute force protection mechanism, where it will block user from certain IP address after 10 times failed login.
Would like to know whether there is mechanism that Auth0 will unblock that user login from respective IP address after certain amount of time ?

Answer to your questions can be found in this doc:

It’s not possible to automatically unblock the user from the blocked IP after certain amount of time.

