You say you have tried different settings for IP Workarounds, that suggests that you have the ability to disable Admin Tools and log in to the back end. In case I'm wrong, those instructions are
here.
Your problem is the Secret URL Parameter. The setting can be found in Web Application Firewall, Configure WAF, on the first tab. The value in the "Administrator secret URL parameter" changes the address for the back end log in page. When there is a value in that field, you must call the back end login like so:
www.mysite.com/administrator/index.php?SECRET
Where SECRET is the value in the field. If the bad guys can't find the login page, they aren't going to log in.
This value is set during the First Run Wizard. If you want to disable it, just leave the field bland.
Dale L. Brackin
Support Specialist
English: native
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!
????
My time zone is
EST (UTC -5) (click here to see my current time in Philadelphia, PA)