Submenu – Dynamic IP Blacklist
Airlock Gateway can monitor IP addresses with suspicious behavior and temporarily block them. If an IP address triggers a block, it is added to a watchlist. If too many blocks from the same IP address occur within a defined period, the IP address is added to the dynamic IP denylist for a defined time.
On this page, you configure the thresholds for dynamic IP blacklisting and whether traffic from blacklisted IP addresses is blocked already at the firewall level.
Section – Observation & Timing
GUI | Description |
|---|---|
Observation period in seconds | Defines how long an IP address is observed. |
Number of blocks within period | Defines how many blocks an IP address must trigger during the observation period before it is added to the dynamic IP denylist. |
Period to block in seconds | Defines how long an IP address remains on the dynamic IP denylist. |
Mapping-specific options
On mappings, the IP Rules tab provides additional options: for each mapping, you can configure whether IP addresses on the dynamic IP denylist are blocked and whether blocks count toward the threshold for an IP address.
Section – Enforcement
GUI | Description |
|---|---|
Drop all traffic from blacklisted IPs | If enabled, traffic from IP addresses on the dynamic IP blacklist is blocked already at the firewall level. If disabled, traffic from blacklisted IP addresses is blocked later by the Security Gateway. |
If enabled, the following applies:
- This option can be used to mitigate denial-of-service attacks.
- Blocks at the firewall level are not logged explicitly, and affected clients do not receive an Airlock Gateway error page.
- When an IP address is added to the dynamic blacklist, Airlock Gateway logs a corresponding message. You can analyze these events in the GATEWAY Overview (default) reporting dashboard.
The Dynamic IPBl acklist feature is not supported if the virtual host expert setting X-Forwarded-For is enabled.
