Overview
IPBan Pro consists of two primary applications that work together to provide centralized IP ban management across one or more machines:
| Application | Purpose |
|---|---|
| Web Admin | Central web-based dashboard for managing bans, whitelists, notifications, plugins, and connected datacenter clients. |
| Datacenter Client | Runs on each protected machine, monitors log files for failed/successful logins, manages the local firewall, and reports events to the Web Admin via WebSocket. |
In the Server Edition, these run as two separate services — typically one central Web Admin and many datacenter clients, each on its own machine, reporting in over WebSocket. In the Personal Edition, the Web Admin and datacenter client are bundled together and run on a single machine: there is no remote connectivity, no multi-machine dashboard, and everything (bans, whitelist, monitoring) is scoped to that one, local install. See Editions for the full feature comparison.
Web Admin Application
Installation
The Web Admin is installed as a system service. The installer supports both Windows and Linux:
| Platform | Default Path |
|---|---|
| Windows | C:\Program Files\IPBanProWebAdmin |
| Linux | /opt/IPBanProWebAdmin |
Installer command-line arguments:
| Argument | Description |
|---|---|
-d=<path> |
Destination install path |
-db=<type> |
Database provider (sqlite, sqlserver, mysql, or postgres) |
-dbconn=<string> |
Database connection string |
-uninstall |
Uninstall the service |
The installer creates a desktop URL shortcut on Windows and registers an uninstaller entry.
Database Configuration
The Web Admin supports four database providers, configured in appsettings.json:
| Provider | Value |
|---|---|
| SQLite (default) | sqlite |
| SQL Server | sqlserver |
| MySQL | mysql |
| PostgreSQL | postgres |
The DatabaseProvider key in appsettings.json selects the provider, and the corresponding connection string is read from the ConnectionStrings section. The default SQLite database file is IPBanProWebAdmin.sqlite.
Authentication
The Web Admin supports two authentication schemes:
- Basic Authentication — Username and password credentials stored in a local credentials file.
- OpenID Connect — Configured via the
OpenIdsection inappsettings.jsonfor integration with providers such as Microsoft Entra ID (Azure AD). Server Edition only — Personal Edition always uses Basic Authentication.
These schemes can be used independently or together. Successful logins via either scheme (including OpenID Connect) are recorded to the recent activity / logs feed, the same as a datacenter client login. The application supports the following roles:
| Role | Access Level |
|---|---|
| Administrator | Full access to all features |
| Guest (inclusive) | Read-only access to dashboards and recent activity |
| Whitelister | Can modify whitelist entries in settings |
| Blacklister | Can modify blacklist entries in settings |
| Event Reader | Can view IP address events and use diagnostic tools |
| Client | Used by datacenter clients connecting via WebSocket |
Form-based admin actions (credential changes, ban/unban, settings, licenses, plugins, etc.) are protected against cross-site request forgery (CSRF) with anti-forgery tokens. The JSON /api/* surface is unaffected, since it is called directly (Basic Auth, no browser form) rather than via a submitted HTML form.
Dashboard & Recent Activity
Route: / or /recentactivity
The home page displays recent activity including:
- Recently banned IP addresses
- Recent failed login attempts
- Recent successful login attempts
Features:
- Filter by connected machine
- Configurable max result count
- Optional server-side paging with per-column filtering and sorting
- Export to ZIP (
/IPBanProRecentActivity.zip)
Machines
Route: /machines
Manage all datacenter client machines connected to the Web Admin:
- View all registered machines with FQDN, IP address, alias, OS, version, and status
- View and edit individual machine details (
/machine/{id}) - Delete machines
- Override country blacklist settings per machine (
/machine-countryblacklistoverride) - View connected clients in real time (
/connectedclients)
Settings
Route: /settings
The centralized settings page is organized into several sections:
Whitelist & Blacklist
- Whitelist — IP addresses, ranges, or CIDR blocks that are never banned.
- Blacklist — IP addresses, ranges, or CIDR blocks that are always banned.
- Country Blacklist — Block all traffic from selected countries. Options include:
- Allowed ports (exceptions for country blocking)
- First-failed-login mode (block on first failed login from a country)
- Invert mode (block all countries except those listed)
- Precise mode for more accurate geo-blocking
- ASN Blacklist — Block traffic by Autonomous System Number.
Notifications
- Notification Flags — Choose which events trigger notifications (bans, failed logins, successful logins, etc.).
- Duplicate Filter Window — Suppress duplicate notifications within a time window.
- SMTP Email — Configure outgoing email notifications:
- Server, port, SSL, credentials
- From/To addresses
- Subject and body templates (with WHOIS variants)
- Webhook — Send notification payloads to an HTTP endpoint.
Client Settings
- Configuration pushed to connected datacenter clients.
Event Viewer / Log Parsing
- Custom event log and log file parsing rules.
IPBan Shield
- Additional security hardening settings.
- Aggregate Ban User Names — Bans every source IP attempting to log in as a given username once that username has failed login from at least N distinct IP addresses, even if no single IP crosses the normal per-IP ban threshold (defends against distributed/low-and-slow username-spray attacks). Available on both Personal and Server Edition.
XML Configuration
- Direct XML editing for advanced IPBan configuration.
Monitoring
Route: /monitor
Real-time monitoring dashboard for connected machines:
- Toggle monitoring on/off per machine
- Live data streamed via WebSocket to the browser
- Filter by machine name
- Restrict to IPBan Pro events — When enabled (the default), only packet events tied to IPBan Pro’s own firewall rules are shown. Disable it to also see the platform’s default block rule events (e.g. baseline Windows Filtering Platform blocks) for broader packet-level visibility.
Logs
Route: /logs
View aggregated log entries from datacenter clients:
- Filter by machine, log level, and timestamp
- Configurable max result count
- Refresh and clear log database functionality
License Management
Route: /licenses
Manage IPBan Pro license keys:
- View current license keys with usage and status
- Add, update, or remove license keys
- View the count of connected clients
- Personal edition accepts a single license key; server edition accepts multiple
Blacklist Export
Export the current blacklist as a downloadable file:
| Endpoint | Format |
|---|---|
/blacklst.txt |
Plain text |
/blacklst.txt.gz |
Gzip-compressed text |
/blacklst.tgz or /blacklst.tar.gz |
Tar+gzip archive |
Whitelist URLs
Route: /whitelist-urls
(Server edition only)
Manage URL-based whitelists that are periodically fetched and synchronized to connected datacenter clients. IP addresses resolved from configured URLs are automatically added to the client whitelists.
IP Address Events
Route: /ipaddressevents/{id}
Look up detailed event history for a specific IP address, including all recorded failed logins, successful logins, and ban events with geo-lookup information.
Tools
Route: /tools
A collection of administrative utilities:
| Tool | Route | Description |
|---|---|---|
| Update Clients | /tools-updateclients |
Push software updates to connected datacenter clients. Select version and optional machine filter. |
| Change Credentials | /tools-changecredentials |
Change the Web Admin login credentials. |
| IP Address Events | /tools-ipaddressevents |
Search for events by IP address. |
| Unban IP Addresses | /tools-unbanipaddresses |
Remove specific IP addresses from the ban list. |
| Reset Banned IPs | /tools-resetbannedips |
Clear all banned IP addresses. |
| Is IP Banned | /tools-isipaddressbanned |
Check whether a specific IP address is currently banned. |
| Last Whitelist Access | /tools-checklastwhitelistaccess |
Check the last time a whitelisted IP accessed the system. |
| Resolve IP Addresses | /tools-resolveipaddresses |
Perform DNS resolution on IP addresses. |
| Firewall Rules | /tools-firewallrules |
Retrieve the current firewall rules from a connected client. |
| Diagnostics | /tools-diagnostics |
Run a diagnostic simulation for a given IP address and username to trace notification and ban behavior. |
| Clear DB Log | /tools-cleardblog |
Delete all log entries from the database. |
Plugins
Route: /plugins
The Web Admin has a plugin system that extends functionality. Each plugin can be enabled/disabled and configured through the UI or API.
Cloudflare
Synchronizes banned IP addresses to Cloudflare firewall rules.
| Setting | Description |
|---|---|
ApiToken |
Cloudflare API token |
MaxCount |
Maximum banned IPs to sync (up to 10,000) |
ZoneIds |
Comma-separated Cloudflare zone IDs |
Azure NSG
Updates Azure Network Security Group deny rules with banned IP addresses.
| Setting | Description |
|---|---|
SubscriptionId |
Azure subscription ID |
ResourceGroup |
Resource group containing the NSGs |
NsgNames |
Comma-separated NSG names |
RuleName |
Name of the security rule to manage |
Priority |
Rule priority (100–4096) |
MaxCount |
Max banned IPs to include (up to 1,000) |
TenantId |
Azure AD tenant ID (optional; uses DefaultAzureCredential if empty) |
ClientId |
Azure AD client ID (optional) |
ClientSecret |
Azure AD client secret (optional) |
Azure Sign-In Events
Monitors Azure AD sign-in activity logs and processes failed/successful login events.
| Setting | Description |
|---|---|
TenantId |
Azure AD tenant ID |
ClientId |
Application client ID |
ClientSecret |
Client secret |
GraphApiUrl |
Microsoft Graph API URL (default: https://graph.microsoft.com/v1.0) |
MaxEvents |
Max events per poll (1–5,000) |
PollIntervalMinutes |
Polling interval in minutes |
IncludeInteractiveOnly |
Only include interactive sign-ins |
Syslog
Forwards ban events, failed logins, and successful logins to a syslog server.
| Setting | Description |
|---|---|
Host |
Syslog server host |
Port |
Syslog server port |
Transport |
Protocol (udp, tcp, etc.) |
MaxCount |
Max events per update cycle |
Run Process
Executes an external process with recently banned IP addresses as a command-line argument.
| Setting | Description |
|---|---|
ProcessPath |
Path to the executable |
MaxCount |
Max IPs to pass (up to 100,000) |
Domain Whitelister
Allows authenticated users whose username matches configured domains to whitelist their own IP address. Requires OpenID Connect authentication.
| Setting | Description |
|---|---|
TriggerOnAnyUrl |
Redirect matching users automatically on any page load |
DurationDays |
Whitelist duration in days |
UserNotAuthorizedMessage |
Message shown to unauthorized users |
Domains |
Newline-separated list of allowed email domains |
Users visit /whitelistme or /plugins/domainwhitelister/entry to self-whitelist.
Geo Notification
Detects impossible travel (same user logging in from distant locations) and abnormal login locations.
| Setting | Description |
|---|---|
KilometersPerHour |
Max travel speed for impossible travel detection |
TrackBorders |
Country, Region, or empty — notify on border crossings |
TrackUsersAcrossMachines |
Track users across multiple machines |
DayCutOff |
Max days to analyze for anomalies |
NotificationEmailAddresses |
Override notification recipients |
MinimumDistanceKilometers |
Ignore travel within this threshold |
REST API
Base Route: /api
The Web Admin exposes a JSON REST API for programmatic access. All API endpoints require authentication.
| Endpoint | Method | Description |
|---|---|---|
/api/status |
GET | Health check |
/api/clientstart |
GET | Register client start event |
/api/clientstop |
GET | Register client stop event |
/api/dataset/{dataset} |
POST | Paged data queries (recentbans, recentfailedlogins, recentsuccessfullogins) |
/api/pluginsettings/{name} |
GET | Retrieve plugin settings |
/api/pluginsettings/{name} |
POST | Update plugin settings |
Full Swagger/OpenAPI documentation is available at the /swagger endpoint when the application is running.
MCP Server (Model Context Protocol)
Route: /mcp
The Web Admin includes a built-in MCP server so an LLM-based client (Claude Desktop, Claude Code, or any other MCP-compatible tool) can investigate bans, logins, and machine status, and take a small set of safe actions, directly in conversation — without writing scripts against the REST API.
- Transport: Streamable HTTP, mounted at
/mcp. - Authentication: The same credentials as the Web Admin UI (Basic Authentication or OpenID Connect). Every call requires the Administrator role — no other role, including Guest or Event Reader, can reach MCP tools.
- Implementation: Each tool is a thin wrapper around the same controller action the REST API or web UI already uses, so results and permissions match exactly what an administrator sees in the browser — no separate business logic or data path.
To connect a client, point it at https://<your-webadmin-host>/mcp using Streamable HTTP transport and supply Web Admin administrator credentials.
Read / query tools:
| Tool | Description |
|---|---|
ipban_recent_activity |
Combined recent bans plus failed/successful logins, with country info |
ipban_recent_activity_by_country |
Recent bans and logins summarized by country |
ipban_failed_logins |
Most recent failed login attempts across all machines |
ipban_successful_logins |
Most recent successful login attempts across all machines |
ipban_new_successful_login_report |
Per-machine report of username+IP combinations with no prior successful logins |
ipban_ip_address_events |
All failed logins, successful logins, and ban records for a single IP address |
ipban_blacklist |
Recently banned / blacklisted IP addresses |
ipban_whitelist |
All whitelisted IP addresses, ranges, and CIDR blocks |
ipban_machines |
All registered machines with FQDN, IP, alias, OS, version, and status |
ipban_machine |
Full details for a single machine by id |
ipban_machine_whitelist |
The whitelist configured for a specific machine |
ipban_check_whitelisted |
Check whether one or more IP addresses are whitelisted |
ipban_resolve_ip_addresses |
Resolve IP addresses to country / geolocation / ASN info |
ipban_check_ban_state |
Check the current ban state of one or more IP addresses |
ipban_packet_log_usage |
Disk usage statistics for the firewall packet monitoring logs |
ipban_connected_clients |
Datacenter clients currently connected over WebSocket |
ipban_client_firewall_rules |
Live firewall rules from a connected client (requires client 2.5.0+) |
Safe mutation tools:
| Tool | Description |
|---|---|
ipban_ban_ip_addresses |
Ban one or more IP addresses, with optional duration and notes |
ipban_unban_ip_addresses |
Unban one or more IP addresses, optionally whitelisting them too |
ipban_remove_whitelisted |
Remove one or more IP addresses from the whitelist |
ipban_set_machine_alias |
Set the friendly alias / display name for a machine |
Destructive or secret-bearing operations — resetting all bans, deleting machines, overwriting settings, credential changes, raw SQL, and reads of secret-bearing config such as SMTP credentials or whitelist URLs — are intentionally not exposed as MCP tools.
Software Updates
Route: /autoupdate
Trigger a self-update of the Web Admin application. The update is downloaded from api.ipban.com and installed automatically. The appropriate download is selected based on the current operating system and CPU architecture.
Datacenter Client Application
Datacenter Installation
The datacenter client is installed as a system service on each machine to be protected.
| Platform | Default Path |
|---|---|
| Windows | C:\Program Files\IPBanProDatacenter |
| Linux | /opt/IPBanProDatacenter |
Installer command-line arguments:
| Argument | Description |
|---|---|
-d=<path> |
Destination install path |
-uninstall |
Uninstall the service |
During installation, you are prompted for the Web Admin server URL and credentials. The client connects to the Web Admin via WebSocket to send events and receive configuration updates.
Version check:
IPBanProDatacenter --version
Firewall Types
The datacenter client supports multiple firewall implementations:
| Firewall | Platform | Description |
|---|---|---|
| WFP (Windows Filtering Platform) | Windows | Recommended for modern Windows. High-performance packet-level filtering. |
| Windows Firewall | Windows | Legacy Windows Firewall (for informational/reference only). |
| iptables | Linux | Traditional Linux packet filtering with monitoring. |
| nftables | Linux | Modern Linux packet filtering with monitoring. |
| firewalld | Linux | Linux firewalld integration with monitoring. |
WebSocket Communication
The datacenter client maintains a persistent WebSocket connection to the Web Admin for:
- Reporting events — Failed logins, successful logins, bans, and unbans.
- Receiving configuration — Settings changes, whitelist/blacklist updates, country block lists, and ASN block lists are pushed from the Web Admin in real time.
- Remote commands — Firewall rule queries, software update triggers, and credential changes.
- Log forwarding — Client log entries are sent to the Web Admin for centralized viewing.
- Packet monitoring — Blocked packet events can be forwarded for analysis.
Credential Management
Credentials are stored in a local creds.txt file on the datacenter client. The file contains username/password pairs with associated roles. Credentials can be changed remotely from the Web Admin.
The datacenter client also maintains a machine_guid.txt file that uniquely identifies the machine. This GUID can be reset during installation or via the installer.
Migration
The datacenter client supports database migration via the command line:
IPBanProDatacenter migrate [args]
This is used when upgrading from previous versions or changing database schemas.
Editions
| Feature | Personal Edition | Server Edition |
|---|---|---|
| Connected machines | 1 (local) | Multiple (remote datacenter clients) |
| License keys | 1 | Multiple |
| Whitelist URLs | Not available | Available |
| Service broadcasting | Not available | Available |
| OpenID Connect authentication | Not available (Basic Auth only) | Available |
| All plugins | Available | Available |
| All tools | Available | Available |
| SMTP & webhook notifications | Available | Available |
| REST API | Available | Available |
| MCP Server | Available | Available |
The Personal Edition runs the Web Admin and IPBan service on the same machine. The Datacenter Edition runs the Web Admin centrally with multiple datacenter clients connecting remotely.
