Login Break-in LGI parameters



Can someone please expain in simple English what happens here.

This is how I read the settings:

1) Users get LGI_BRK_LIM=5 login failures before being blocked
as an INTRUDER (The failure count is logged in the INTRUSION
entry even though lockout has yet to occur).

2) Once the break-in limit is reached the source is prevented
from login even with the correct Username and Password for
LGI_HID_TIM=30 minutes.

3) Monitoring of login failure continues for LGI_BRK_TMO=2
minutes after a failure. For each subsequent failure, another
LGI_BRK_TMO=2 minutes is added to the monitoring period. After
this period has passed the INTRUSION record is discarded.


A careful reading if this yields a contradiction. If the source
login fails 5 times (1) the source is blocked. Monitoring
of that source is for 2 minutes, then the source is given a clean
slate (3). The souce is prevented even from correct login for
30 minutes (2). So which is it, 2 (or 4 or 6) minutes or 30
minutes or is it 2 (or 4 or 6) + 30 minutes?


.



Relevant Pages

  • Re: admin shares and security
    ... If you are auditing login attempts you should be seeing logon ... share of a server I was already connected to with another username. ... connection. ... Hence no failure. ...
    (microsoft.public.windows.server.security)
  • Re: Login Break-in LGI parameters
    ... Users get LGI_BRK_LIM=5 login failures before being blocked ... as an INTRUDER (The failure count is logged in the INTRUSION ... Monitoring of login failure continues for LGI_BRK_TMO=2 ... LGI_BRK_TMO=2 minutes is added to the monitoring period. ...
    (comp.os.vms)
  • Re: windows xp email login failure
    ... "Shenan Stanley" wrote: ... When checking my email I receive a "login failure." ... Verify both with the web mail client. ...
    (microsoft.public.windowsxp.help_and_support)
  • Re: Login Break-in LGI parameters
    ... Users get LGI_BRK_LIM=5 login failures before being blocked ... as an INTRUDER (The failure count is logged in the INTRUSION ... It add the 2 minutes to the timeout value of the previous record. ... Once you have become an intruder then the timeout for the intrusion record goes to the LGI_HID_TIM ...
    (comp.os.vms)
  • Re: Login Break-in LGI parameters
    ... Users get LGI_BRK_LIM=5 login failures before being blocked ... as an INTRUDER (The failure count is logged in the INTRUSION ... It add the 2 minutes to the timeout value of the previous record. ... Once you have become an intruder then the timeout for the intrusion record goes to the LGI_HID_TIM ...
    (comp.os.vms)