Submenu – Dynamic IP Blacklist

Airlock Gateway can monitor IP addresses with suspicious behavior and temporarily block them. If an IP address triggers a block, it is added to a watchlist. If too many blocks from the same IP address occur within a defined period, the IP address is added to the dynamic IP denylist for a defined time.

On this page, you configure the thresholds for dynamic IP blacklisting and whether traffic from blacklisted IP addresses is blocked already at the firewall level.

Section – Observation & Timing

GUI

Description

Observation period in seconds

Defines how long an IP address is observed.

Number of blocks within period

Defines how many blocks an IP address must trigger during the observation period before it is added to the dynamic IP denylist.

Period to block in seconds

Defines how long an IP address remains on the dynamic IP denylist.

Mapping-specific options

On mappings, the IP Rules tab provides additional options: for each mapping, you can configure whether IP addresses on the dynamic IP denylist are blocked and whether blocks count toward the threshold for an IP address.

Section – Enforcement

GUI

Description

Drop all traffic from blacklisted IPs

If enabled, traffic from IP addresses on the dynamic IP blacklist is blocked already at the firewall level. If disabled, traffic from blacklisted IP addresses is blocked later by the Security Gateway.

If enabled, the following applies:

  • This option can be used to mitigate denial-of-service attacks.
  • Blocks at the firewall level are not logged explicitly, and affected clients do not receive an Airlock Gateway error page.
  • When an IP address is added to the dynamic blacklist, Airlock Gateway logs a corresponding message. You can analyze these events in the GATEWAY Overview (default) reporting dashboard.
 
Notice

The Dynamic IPBl acklist feature is not supported if the virtual host expert setting X-Forwarded-For is enabled.