Support

Admin Tools

#31845 request blocked by admin tools

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
n/a
PHP version
n/a
Admin Tools version
n/a

Latest post by Phil973 on Tuesday, 08 October 2019 15:36 CDT

Phil973
Hi, i install lately Admin tools pro for joomla and some users contact me because they face the message "403 this request is blocked admin tools..............."
I feel strange because users
- are not listed in the "Auto IP Blocking History"
- are not listed in the "Auto IP Blocking Administration"
- are not on a banned GEO location
- do not appear in the "Security Exceptions Log" list

However, i ask this user their IP address and "Unblock" them through WAF/Unblock an IP with a validation message each time. Also, i deactivate the function "Treat failed logins as security exceptions".

Still access to my website from a regular user from Taiwan remain impossible at the moment.
Thanks in advance

nicholas
Akeeba Staff
Manager
There are two reasons Admin Tools will block an IP address and not report anything in the Security Exceptions Log: IP blacklist or geographic IP blocking.

Are you using any Geographic IP restrictions? The MaxMind Country Database Lite used by Admin Tools to convert IP addresses to geographic information only claims 95% accuracy. This means that one in twenty users will have their country reported wrong based on the IP address. It's possible that your user belongs to one of the IP ranges that MaxMind's database misidentifies.

If you are not using geographic IP blocking at all you need to check your IP blacklist. Did you add your users' IP or their entire IP range there?

Finally, I'd like to note that the Unblock an IP feature always returns a success message. We just run a bunch of delete commands based on the IP you gave us. If the database does not report an error we consider it a success. The database does NOT report an error if no database record matched the delete request.

So, based on what you described I think that the problem is the accuracy of the third party GeoIP database.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Phil973
Hi Nicolas, appreciate your fast & accurate answer.
You are right, user was locked by Geo option
After uncheck Malaysia user can access the website as normal
Thanks again!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!