Miscellaneous » WP fail2ban Blocklist

TL;DR

The WP fail2ban Blocklist add-on shares current, WordPress-specific attack sources across participating sites. When another site sees a hostile address first, Blocklist can give your fail2ban jail the address in time for the host firewall to block it before WordPress has to process the same attack.

WP fail2ban Free contributes to the network and receives a reduced set of current addresses. Premium receives the full current Blocklist intelligence available to your site.

Participation uses your site's existing Freemius connection for registration and the WordPress REST API for the exchange. A working fail2ban jail and firewall action turn the warning into pre-emptive protection.

Act before the attack reaches WordPress

Normal WP fail2ban protection begins when your site sees an attack. WordPress supplies the context, WP fail2ban records a meaningful event, and fail2ban can block the source at the host firewall.

Every newly active address has to be observed somewhere before the network can share it. Sometimes your site will make that first observation, and its event can help protect other participants while your normal WP fail2ban jails protect you.

When another site sees the address first, Blocklist gives you the opportunity to stop it at the firewall before it reaches your own installation. The network cannot win every race, but each shared warning creates another chance to act early.

Join through the connection you already have

Blocklist runs as a companion add-on and uses the Freemius connection already available to WP fail2ban to register your site. You do not need a separate Blocklist account.

The service then contacts participating sites through the WordPress REST API to collect observations and deliver updates. The Blocklist route must remain reachable; if another security plugin or a server rule closes it, the site cannot exchange warnings with the network.

More about how Blocklist works.

Share selected WordPress security events

Blocklist uses the source addresses from selected WP fail2ban security events. It does not submit every message WP fail2ban writes or build its current intelligence from a general third-party threat feed.

The value of each observation depends on the client address attached to it. If a reverse proxy, load balancer, or CDN sits in front of WordPress, WP fail2ban can preserve the real client address before the event is shared.

More about getting the real client IP behind a proxy.

Receive intelligence selected for your site

Blocklist does not send every participant an identical global download. It selects current addresses your site has not already had to discover for itself.

Two sites can therefore receive different results at the same time and both be working correctly. WP fail2ban Free receives a reduced selection; Premium receives the full current selection available to the site.

Once an address arrives, the add-on records the event for fail2ban. A suitable jail and firewall action still have to enforce it: without that path to the firewall, the warning cannot stop a connection before WordPress.

Add longer-term reputation when you need it

A reputable public abuse list can add reputation built from independent reports over a longer period. That is a different kind of evidence from Blocklist's current WordPress warnings.

Keep Blocklist in its temporary fail2ban jail; you will normally load public abuse data directly into a firewall table. Each source can then follow the response its evidence supports.

More about using Blocklist alongside public abuse lists.