Blocking

Understanding blocking behavior

How Syspeace blocks a detected source, and how that differs between v3 and v4.

Syspeace v3 and v4

Once a source’s activity matches a configured rule, Syspeace blocks its IP address. How that block is enforced differs by version:

  • Syspeace v4 blocks directly through the Windows Filtering Platform. Enforcement keeps working even if Windows Firewall is disabled, or managed by another security product.
  • Syspeace v3 blocks through Windows Firewall or IP Security Policy. If Windows Firewall is disabled or controlled by other software, configuration may be required to switch blocking over to IP Security Policy.

Why blocks expire

Syspeace blocks IP addresses, not individual attackers. Addresses are reassigned over time, so a block that lasts forever risks eventually blocking a legitimate user who was assigned that address later. Maximum block duration differs by version — see the version comparison for the current figures.

The Global Blocklist

Blocks reported across the Syspeace customer base are analyzed for addresses attacking many accounts, and distributed back to all Syspeace installations as the Global Blocklist — so a source flagged elsewhere can be blocked pre-emptively. See the FAQ for what information contributes to this.

What this does not do

Blocking a source does not notify it that it’s been blocked, and it does not affect legitimate users at other addresses. It also isn’t a substitute for the account and network controls described on the product page — Syspeace responds to a pattern of repeated failed sign-ins; it doesn’t prevent an attacker from trying a different address, or from targeting a different sign-in surface entirely.