The default thresholds are conservative — they catch obvious attacks while rarely tripping innocent users. For higher-security deployments, tighten them. For consumer apps with shared mobile carriers, loosen them. This article gives concrete tuning recipes.
The Default Numbers
- Attempts: 10
- Monitoring period: 5 minutes
- Ban duration: 1 hour
Tightening (High Security)
For finance, healthcare or administrator-only apps:
- Attempts: 5
- Monitoring period: 10 minutes
- Ban duration: 24 hours
- Combine with mandatory 2FA and per-username counters.
Loosening (High Volume Consumer)
For a marketplace where many real users share carrier IPs:
- Attempts: 20
- Monitoring period: 30 minutes
- Ban duration: 30 minutes
- Per-username throttling rather than per-IP catches individual account abuse.
Tuning Process
- Look at the blocked IPs log over the last 30 days.
- Spot-check the top-blocked IPs to see whether they're real users or attackers.
- If many real users are caught, raise attempts or extend the monitoring period.
- If attackers are slipping through (many failures per hour but never quite tripping the limit), tighten.
Worked Examples
- Bank-grade app: 3 attempts, 30 min window, 24 hr ban. Painful for fat-fingered users — that's the point.
- Mobile-first consumer app: 20 attempts, 60 min window, 15 min ban — generous enough not to lock out shared carrier IPs.
- B2B internal: 8 attempts, 10 min window, 1 hr ban. Staff have stable IPs and good password managers; misfires are rare.