Overview

IPBan Pro consists of two primary applications that work together to provide centralized IP ban management across one or more machines:

Application Purpose
Web Admin Central web-based dashboard for managing bans, whitelists, notifications, plugins, and connected datacenter clients.
Datacenter Client Runs on each protected machine, monitors log files for failed/successful logins, manages the local firewall, and reports events to the Web Admin via WebSocket.

In the Server Edition, these run as two separate services — typically one central Web Admin and many datacenter clients, each on its own machine, reporting in over WebSocket. In the Personal Edition, the Web Admin and datacenter client are bundled together and run on a single machine: there is no remote connectivity, no multi-machine dashboard, and everything (bans, whitelist, monitoring) is scoped to that one, local install. See Editions for the full feature comparison.

Web Admin Application

Installation

The Web Admin is installed as a system service. The installer supports both Windows and Linux:

Platform Default Path
Windows C:\Program Files\IPBanProWebAdmin
Linux /opt/IPBanProWebAdmin

Installer command-line arguments:

Argument Description
-d=<path> Destination install path
-db=<type> Database provider (sqlite, sqlserver, mysql, or postgres)
-dbconn=<string> Database connection string
-uninstall Uninstall the service

The installer creates a desktop URL shortcut on Windows and registers an uninstaller entry.

Database Configuration

The Web Admin supports four database providers, configured in appsettings.json:

Provider Value
SQLite (default) sqlite
SQL Server sqlserver
MySQL mysql
PostgreSQL postgres

The DatabaseProvider key in appsettings.json selects the provider, and the corresponding connection string is read from the ConnectionStrings section. The default SQLite database file is IPBanProWebAdmin.sqlite.

Authentication

The Web Admin supports two authentication schemes:

  • Basic Authentication — Username and password credentials stored in a local credentials file.
  • OpenID Connect — Configured via the OpenId section in appsettings.json for integration with providers such as Microsoft Entra ID (Azure AD). Server Edition only — Personal Edition always uses Basic Authentication.

These schemes can be used independently or together. Successful logins via either scheme (including OpenID Connect) are recorded to the recent activity / logs feed, the same as a datacenter client login. The application supports the following roles:

Role Access Level
Administrator Full access to all features
Guest (inclusive) Read-only access to dashboards and recent activity
Whitelister Can modify whitelist entries in settings
Blacklister Can modify blacklist entries in settings
Event Reader Can view IP address events and use diagnostic tools
Client Used by datacenter clients connecting via WebSocket

Form-based admin actions (credential changes, ban/unban, settings, licenses, plugins, etc.) are protected against cross-site request forgery (CSRF) with anti-forgery tokens. The JSON /api/* surface is unaffected, since it is called directly (Basic Auth, no browser form) rather than via a submitted HTML form.

Dashboard & Recent Activity

Route: / or /recentactivity

The home page displays recent activity including:

  • Recently banned IP addresses
  • Recent failed login attempts
  • Recent successful login attempts

Features:

  • Filter by connected machine
  • Configurable max result count
  • Optional server-side paging with per-column filtering and sorting
  • Export to ZIP (/IPBanProRecentActivity.zip)

Machines

Route: /machines

Manage all datacenter client machines connected to the Web Admin:

  • View all registered machines with FQDN, IP address, alias, OS, version, and status
  • View and edit individual machine details (/machine/{id})
  • Delete machines
  • Override country blacklist settings per machine (/machine-countryblacklistoverride)
  • View connected clients in real time (/connectedclients)

Settings

Route: /settings

The centralized settings page is organized into several sections:

Whitelist & Blacklist

  • Whitelist — IP addresses, ranges, or CIDR blocks that are never banned.
  • Blacklist — IP addresses, ranges, or CIDR blocks that are always banned.
  • Country Blacklist — Block all traffic from selected countries. Options include:
    • Allowed ports (exceptions for country blocking)
    • First-failed-login mode (block on first failed login from a country)
    • Invert mode (block all countries except those listed)
    • Precise mode for more accurate geo-blocking
  • ASN Blacklist — Block traffic by Autonomous System Number.

Notifications

  • Notification Flags — Choose which events trigger notifications (bans, failed logins, successful logins, etc.).
  • Duplicate Filter Window — Suppress duplicate notifications within a time window.
  • SMTP Email — Configure outgoing email notifications:
    • Server, port, SSL, credentials
    • From/To addresses
    • Subject and body templates (with WHOIS variants)
  • Webhook — Send notification payloads to an HTTP endpoint.

Client Settings

  • Configuration pushed to connected datacenter clients.

Event Viewer / Log Parsing

  • Custom event log and log file parsing rules.

IPBan Shield

  • Additional security hardening settings.
  • Aggregate Ban User Names — Bans every source IP attempting to log in as a given username once that username has failed login from at least N distinct IP addresses, even if no single IP crosses the normal per-IP ban threshold (defends against distributed/low-and-slow username-spray attacks). Available on both Personal and Server Edition.

XML Configuration

  • Direct XML editing for advanced IPBan configuration.

Monitoring

Route: /monitor

Real-time monitoring dashboard for connected machines:

  • Toggle monitoring on/off per machine
  • Live data streamed via WebSocket to the browser
  • Filter by machine name
  • Restrict to IPBan Pro events — When enabled (the default), only packet events tied to IPBan Pro’s own firewall rules are shown. Disable it to also see the platform’s default block rule events (e.g. baseline Windows Filtering Platform blocks) for broader packet-level visibility.

Logs

Route: /logs

View aggregated log entries from datacenter clients:

  • Filter by machine, log level, and timestamp
  • Configurable max result count
  • Refresh and clear log database functionality

License Management

Route: /licenses

Manage IPBan Pro license keys:

  • View current license keys with usage and status
  • Add, update, or remove license keys
  • View the count of connected clients
  • Personal edition accepts a single license key; server edition accepts multiple

Blacklist Export

Export the current blacklist as a downloadable file:

Endpoint Format
/blacklst.txt Plain text
/blacklst.txt.gz Gzip-compressed text
/blacklst.tgz or /blacklst.tar.gz Tar+gzip archive

Whitelist URLs

Route: /whitelist-urls

(Server edition only)

Manage URL-based whitelists that are periodically fetched and synchronized to connected datacenter clients. IP addresses resolved from configured URLs are automatically added to the client whitelists.

IP Address Events

Route: /ipaddressevents/{id}

Look up detailed event history for a specific IP address, including all recorded failed logins, successful logins, and ban events with geo-lookup information.

Tools

Route: /tools

A collection of administrative utilities:

Tool Route Description
Update Clients /tools-updateclients Push software updates to connected datacenter clients. Select version and optional machine filter.
Change Credentials /tools-changecredentials Change the Web Admin login credentials.
IP Address Events /tools-ipaddressevents Search for events by IP address.
Unban IP Addresses /tools-unbanipaddresses Remove specific IP addresses from the ban list.
Reset Banned IPs /tools-resetbannedips Clear all banned IP addresses.
Is IP Banned /tools-isipaddressbanned Check whether a specific IP address is currently banned.
Last Whitelist Access /tools-checklastwhitelistaccess Check the last time a whitelisted IP accessed the system.
Resolve IP Addresses /tools-resolveipaddresses Perform DNS resolution on IP addresses.
Firewall Rules /tools-firewallrules Retrieve the current firewall rules from a connected client.
Diagnostics /tools-diagnostics Run a diagnostic simulation for a given IP address and username to trace notification and ban behavior.
Clear DB Log /tools-cleardblog Delete all log entries from the database.

Plugins

Route: /plugins

The Web Admin has a plugin system that extends functionality. Each plugin can be enabled/disabled and configured through the UI or API.

Cloudflare

Synchronizes banned IP addresses to Cloudflare firewall rules.

Setting Description
ApiToken Cloudflare API token
MaxCount Maximum banned IPs to sync (up to 10,000)
ZoneIds Comma-separated Cloudflare zone IDs

Azure NSG

Updates Azure Network Security Group deny rules with banned IP addresses.

Setting Description
SubscriptionId Azure subscription ID
ResourceGroup Resource group containing the NSGs
NsgNames Comma-separated NSG names
RuleName Name of the security rule to manage
Priority Rule priority (100–4096)
MaxCount Max banned IPs to include (up to 1,000)
TenantId Azure AD tenant ID (optional; uses DefaultAzureCredential if empty)
ClientId Azure AD client ID (optional)
ClientSecret Azure AD client secret (optional)

Azure Sign-In Events

Monitors Azure AD sign-in activity logs and processes failed/successful login events.

Setting Description
TenantId Azure AD tenant ID
ClientId Application client ID
ClientSecret Client secret
GraphApiUrl Microsoft Graph API URL (default: https://graph.microsoft.com/v1.0)
MaxEvents Max events per poll (1–5,000)
PollIntervalMinutes Polling interval in minutes
IncludeInteractiveOnly Only include interactive sign-ins

Syslog

Forwards ban events, failed logins, and successful logins to a syslog server.

Setting Description
Host Syslog server host
Port Syslog server port
Transport Protocol (udp, tcp, etc.)
MaxCount Max events per update cycle

Run Process

Executes an external process with recently banned IP addresses as a command-line argument.

Setting Description
ProcessPath Path to the executable
MaxCount Max IPs to pass (up to 100,000)

Domain Whitelister

Allows authenticated users whose username matches configured domains to whitelist their own IP address. Requires OpenID Connect authentication.

Setting Description
TriggerOnAnyUrl Redirect matching users automatically on any page load
DurationDays Whitelist duration in days
UserNotAuthorizedMessage Message shown to unauthorized users
Domains Newline-separated list of allowed email domains

Users visit /whitelistme or /plugins/domainwhitelister/entry to self-whitelist.

Geo Notification

Detects impossible travel (same user logging in from distant locations) and abnormal login locations.

Setting Description
KilometersPerHour Max travel speed for impossible travel detection
TrackBorders Country, Region, or empty — notify on border crossings
TrackUsersAcrossMachines Track users across multiple machines
DayCutOff Max days to analyze for anomalies
NotificationEmailAddresses Override notification recipients
MinimumDistanceKilometers Ignore travel within this threshold

REST API

Base Route: /api

The Web Admin exposes a JSON REST API for programmatic access. All API endpoints require authentication.

Endpoint Method Description
/api/status GET Health check
/api/clientstart GET Register client start event
/api/clientstop GET Register client stop event
/api/dataset/{dataset} POST Paged data queries (recentbans, recentfailedlogins, recentsuccessfullogins)
/api/pluginsettings/{name} GET Retrieve plugin settings
/api/pluginsettings/{name} POST Update plugin settings

Full Swagger/OpenAPI documentation is available at the /swagger endpoint when the application is running.

MCP Server (Model Context Protocol)

Route: /mcp

The Web Admin includes a built-in MCP server so an LLM-based client (Claude Desktop, Claude Code, or any other MCP-compatible tool) can investigate bans, logins, and machine status, and take a small set of safe actions, directly in conversation — without writing scripts against the REST API.

  • Transport: Streamable HTTP, mounted at /mcp.
  • Authentication: The same credentials as the Web Admin UI (Basic Authentication or OpenID Connect). Every call requires the Administrator role — no other role, including Guest or Event Reader, can reach MCP tools.
  • Implementation: Each tool is a thin wrapper around the same controller action the REST API or web UI already uses, so results and permissions match exactly what an administrator sees in the browser — no separate business logic or data path.

To connect a client, point it at https://<your-webadmin-host>/mcp using Streamable HTTP transport and supply Web Admin administrator credentials.

Read / query tools:

Tool Description
ipban_recent_activity Combined recent bans plus failed/successful logins, with country info
ipban_recent_activity_by_country Recent bans and logins summarized by country
ipban_failed_logins Most recent failed login attempts across all machines
ipban_successful_logins Most recent successful login attempts across all machines
ipban_new_successful_login_report Per-machine report of username+IP combinations with no prior successful logins
ipban_ip_address_events All failed logins, successful logins, and ban records for a single IP address
ipban_blacklist Recently banned / blacklisted IP addresses
ipban_whitelist All whitelisted IP addresses, ranges, and CIDR blocks
ipban_machines All registered machines with FQDN, IP, alias, OS, version, and status
ipban_machine Full details for a single machine by id
ipban_machine_whitelist The whitelist configured for a specific machine
ipban_check_whitelisted Check whether one or more IP addresses are whitelisted
ipban_resolve_ip_addresses Resolve IP addresses to country / geolocation / ASN info
ipban_check_ban_state Check the current ban state of one or more IP addresses
ipban_packet_log_usage Disk usage statistics for the firewall packet monitoring logs
ipban_connected_clients Datacenter clients currently connected over WebSocket
ipban_client_firewall_rules Live firewall rules from a connected client (requires client 2.5.0+)

Safe mutation tools:

Tool Description
ipban_ban_ip_addresses Ban one or more IP addresses, with optional duration and notes
ipban_unban_ip_addresses Unban one or more IP addresses, optionally whitelisting them too
ipban_remove_whitelisted Remove one or more IP addresses from the whitelist
ipban_set_machine_alias Set the friendly alias / display name for a machine

Destructive or secret-bearing operations — resetting all bans, deleting machines, overwriting settings, credential changes, raw SQL, and reads of secret-bearing config such as SMTP credentials or whitelist URLs — are intentionally not exposed as MCP tools.

Software Updates

Route: /autoupdate

Trigger a self-update of the Web Admin application. The update is downloaded from api.ipban.com and installed automatically. The appropriate download is selected based on the current operating system and CPU architecture.

Datacenter Client Application

Datacenter Installation

The datacenter client is installed as a system service on each machine to be protected.

Platform Default Path
Windows C:\Program Files\IPBanProDatacenter
Linux /opt/IPBanProDatacenter

Installer command-line arguments:

Argument Description
-d=<path> Destination install path
-uninstall Uninstall the service

During installation, you are prompted for the Web Admin server URL and credentials. The client connects to the Web Admin via WebSocket to send events and receive configuration updates.

Version check:

IPBanProDatacenter --version

Firewall Types

The datacenter client supports multiple firewall implementations:

Firewall Platform Description
WFP (Windows Filtering Platform) Windows Recommended for modern Windows. High-performance packet-level filtering.
Windows Firewall Windows Legacy Windows Firewall (for informational/reference only).
iptables Linux Traditional Linux packet filtering with monitoring.
nftables Linux Modern Linux packet filtering with monitoring.
firewalld Linux Linux firewalld integration with monitoring.

WebSocket Communication

The datacenter client maintains a persistent WebSocket connection to the Web Admin for:

  • Reporting events — Failed logins, successful logins, bans, and unbans.
  • Receiving configuration — Settings changes, whitelist/blacklist updates, country block lists, and ASN block lists are pushed from the Web Admin in real time.
  • Remote commands — Firewall rule queries, software update triggers, and credential changes.
  • Log forwarding — Client log entries are sent to the Web Admin for centralized viewing.
  • Packet monitoring — Blocked packet events can be forwarded for analysis.

Credential Management

Credentials are stored in a local creds.txt file on the datacenter client. The file contains username/password pairs with associated roles. Credentials can be changed remotely from the Web Admin.

The datacenter client also maintains a machine_guid.txt file that uniquely identifies the machine. This GUID can be reset during installation or via the installer.

Migration

The datacenter client supports database migration via the command line:

IPBanProDatacenter migrate [args]

This is used when upgrading from previous versions or changing database schemas.

Editions

Feature Personal Edition Server Edition
Connected machines 1 (local) Multiple (remote datacenter clients)
License keys 1 Multiple
Whitelist URLs Not available Available
Service broadcasting Not available Available
OpenID Connect authentication Not available (Basic Auth only) Available
All plugins Available Available
All tools Available Available
SMTP & webhook notifications Available Available
REST API Available Available
MCP Server Available Available

The Personal Edition runs the Web Admin and IPBan service on the same machine. The Datacenter Edition runs the Web Admin centrally with multiple datacenter clients connecting remotely.

Stay up to date with the latest news, releases and more.