Hi,
I saw this morning in Nethsecurity realtime monitoring a bruteforce block, but this was in the diagram visible.
is this correct or a bug ?
Hi,
I saw this morning in Nethsecurity realtime monitoring a bruteforce block, but this was in the diagram visible.
is this correct or a bug ?
I think it’s correct.
The blocklist section is about IPs that are blocked because the IP is in an enabled blocklist in the “Threat Shield/Blocklist feeds” whereas the brute force attack section is about IPs that are blocked because of wrong login attempts that are found in logs, see also Monitoring — NethSecurity documentation and Threat shield IP — NethSecurity documentation