Security: blocked IPs & countries

Under Monitoring, three pages control who can even reach the system: Blocked IPs, Blocked countries and Whitelist.

Blocked IPs

In the sidebar, go to Monitoring > Blocked IPs. This is the blacklist of IP addresses currently blocked, per server — including addresses fail2ban has blocked automatically after repeated failed logins, alongside any address blocked by hand.

Blocked IPs: the current blacklist, and the manual block form.
FieldMeaning
IP addressThe address to block.
ServerOne server, or All servers.
Reason / chainA note — for a fail2ban entry, this is where the reason it was auto-blocked appears.

Blocked countries

In the sidebar, go to Monitoring > Blocked countries. Calls from the selected countries are blocked outright, shown on a world map with a region tab (Europe, Asia, Africa, …) and a per-country search.

Blocked countries: a world map of what is currently blocked.
Note

Not all countries can be blocked at the same time — the product keeps at least some reachable so the install itself does not lock everyone out.

Whitelist (trusted IPs)

In the sidebar, go to Monitoring > Whitelist. Addresses and networks entered here are never blocked — neither by fail2ban nor by the blocked-countries list. Manual only, never automatic.

Whitelist: IPs and networks that are always let through.

A typical use: the fixed IP of a call centre or office, so that one employee's failed login does not lock out the whole building.

Check

Open Blocked IPs after a real lockout to see whether fail2ban already caught it; before travelling, check Blocked countries if calls from a new country stop connecting.