[Topic has been merged into this relevant Topic]
I’m a new Pro user and I’m just a little confused on what I should be doing. I get somewhere between 2-20 attempts daily from people trying to log into my WordPress backend which ends up locking my main account that I use to publish posts on the site. In order to prevent them from continually locking that account, what I usually end up doing is adding a “Deny from X.X.X.X” rule to the Current root and Current wp-admin htaccess files (in BPS Pro). If they are changing server IPs and they are a similar range I might add a shorter rule, “Deny from X.X.X.”. This seems to solve the issues until the next one comes along and starts banging at the door.
I believe there is a custom code I can put in place that prevents anyone from any IP except those I list from logging into the site. I have thought about using this code but I was just concerned about accidentally locking myself out. My home IP is not static but my work IP is. Plus on occasion I login and update the site from other locations (but not quite so frequently as in the past).
So my question is, should I just go ahead and implement that fix to keep me from having to keep adding Deny rules?
Is there a limit on how many deny rules I should add?
Does BPS Pro automatically block repeat offenders if I don’t?
I’m leaning towards just blocking the world and letting in those who need in.
PS: If there is a video resource that goes through configuring each of the sections for best practices, that would be helpful. I have watch the basic configuration videos but they don’t really dig in like I was hoping. I was hoping for more of a walk through with someone telling me what the options are and what is the best settings. Helping me really understand what things do.
I appreciate the work you’ve done. It’s been a great tool for protecting my sites, which is why I decided to purchase. Well worth the money. Thanks!