Distributed Attack Tracking
Enable the tracking of login failures from distributed IP addresses to a specific application account. If the number of failures matches the application trigger then all of the IP addresses involved in the attack will be blocked. Tracking applies to LF_SSHD, LF_FTPD, LF_SMTPAUTH, LF_POP3D, LF_IMAPD, LF_HTACCESS.
- Navigate to Juggernaut Firewall -> Settings -> Login Failure Daemon -> Tracking Settings -> Distributed Attack Tracking.
- Check the Distributed attack tracking and set the desired Distributed attack trigger.
- Click the Update button to save your settings.
- Click the Restart button to restart the firewall and login failure daemon.