Loading

Viewing Blocked Addresses

The blocked address list is the register of what is currently blocked and why it got there.

Where to find it

Architect Panel → Security:

  • Blocked IP Addresses — the register
  • Security Settings — the thresholds that create automatic entries

What an entry records

  • The address.
  • The time it was blocked.
  • A manual flag — whether a person added it or the platform did.

The manual flag is the first thing to check

It separates two completely different situations. An automatic entry means somebody failed to sign in repeatedly — routine, self-clearing, usually uninteresting. A manual entry means an administrator made a decision, and that decision has no expiry attached to it.

When investigating why somebody cannot reach the system, this flag tells you immediately whether to wait or to act.

Reading the list

Look at it as a shape rather than a count:

  • A steady trickle of automatic entries — normal background noise on any internet-facing system.
  • A sudden burst — an attack in progress, or something that just broke. An integration with a stale credential can generate this as convincingly as an attacker.
  • Manual entries you do not recognise — worth asking about. They do not expire, and the reason lives only in whoever added them.

Check it after a report of lock-out

"I cannot get in from the office" is answered here in seconds. The distinction that matters is whether the address is blocked or the account is — they are separate lists and they produce the same complaint.

Automatic entries clear themselves

They lapse when the ban length passes. Removing one by hand is only worth doing when somebody legitimate is waiting.

Manual entries do not

They stay until removed. That is the point of them, and it is also the reason the list needs an occasional review — see the article on removing blocks.

Keep a note outside the list

The register has nowhere to record why a manual block was added. Keep that somewhere durable — a ticket, a security log — because an address with no explanation is one nobody will ever feel confident removing.

Worked example

A user reports being unable to sign in from a branch office. The list shows the branch's address blocked automatically eight minutes earlier. A colleague had mistyped their password repeatedly, and because the whole office shares one address, everybody behind it was affected. It clears on its own two minutes later, and the incident prompts a look at whether the threshold suits sites of that size.

Recommendations

  • Check the manual flag first.
  • Check both lists — address and account — on any lock-out report.
  • Record the reason for manual blocks elsewhere.
  • Watch for bursts rather than counting entries.