> ## Documentation Index
> Fetch the complete documentation index at: https://docs.firetone.com.au/llms.txt
> Use this file to discover all available pages before exploring further.

# Blocking addresses

> What the Bans page shows, the one list that is never blocked, and the blocks the platform places on its own.

The **Bans** page (operator only) is three things: addresses you have blocked,
addresses each node's own defences are blocking, and a list of addresses that
must never be blocked.

## Never block these

The allow-list at the top of the page is the one list every defence consults.
An address on it, or inside a range on it, is:

* never dropped by a block you place, or by a node's own ban;
* never counted, banned or reported by a node's fail2ban;
* never looked up on AbuseIPDB (below).

Every enabled trunk's signalling addresses are on it automatically, so a
carrier cannot be banned by a jail that mistook its traffic. Put your own
office or home address here before anything else. Reaching a node takes about
fifteen seconds after you save.

## Blocks you place

**Block** on an observed address or a candidate drops it on every port, on one
node or the whole fleet, for the minutes you give or until you release it. A
block of an address on the never-block list is refused, because it would have
no effect and the row would say otherwise.

## The AbuseIPDB column

Both lists below carry an **AbuseIPDB** column: the address's abuse confidence
as a percentage, red at or above the blocking threshold, with the number of
reports beside it. Hover for when it was checked and who asked. A verdict is
kept for a day, so the same address is never looked up again and again. An
address nobody has asked about shows **Look up**, which spends one of the
day's requests and remembers the answer. Addresses on *Never block these*,
private addresses and your own switches are refused, because nothing would act
on the answer.

## Blocks the platform places on reputation

If the operator has given the platform an [AbuseIPDB](https://www.abuseipdb.com)
key, the **first** time an unknown public address fails to register a phone it
is looked up. At or above the configured abuse confidence (80% unless changed)
it is blocked fleet-wide for **24 hours**, before it gets its second try. Such a
block reads, in the reason column:

> AbuseIPDB confidence 96% (312 reports, 90 days); first SIP failure on node-1

**Release** lifts it like any other block, and the address is not re-blocked on
reputation for a day, so a release is not undone by the scanner's next attempt.
If a customer's phone is caught this way it is because their address carries
other people's reports; release it and add their address to *Never block
these*.

A node's fail2ban still bans any address after five failures, whatever its
score, and needs no key to do it. The reputation check reads the same refusals
fail2ban does, whether the attempt was a registration or a call, so neither
kind gets a second try from a well-known bad address.
