Support

Admin Tools

#42545 Reopeated blocking of IP

Posted in ‘Admin Tools for Joomla! 4 & 5’
This is a public ticket

Everybody will be able to see its contents. Do not include usernames, passwords or any other sensitive information.

Environment Information

Joomla! version
6.0.1
PHP version
8.3.27
Admin Tools version
7.8.4

Latest post by nicholas on Sunday, 14 December 2025 07:11 CST

timpennington

Hello: I recently moved my site from HostGator to Rochen and am having issues with repeated IP blocking when I attempt to log in from the admin and live site.

When it occurs, I follow the steps in "Using FTP to regain access to your site's administrator" and change the file to provider-disable; it works and I log in correctly. I then go to AdminTools and see the button that says to "Unblock my IP Address" which I use, and also to go back and change the file to disable, which I do. This works for a few minutes on my site. But later when I try to access my admin site I get the same message that "We have detected suspicious activity from your IP address. Your access to this site is temporarily suspended." That sends me back to disabiling the file.

Is there something that is causing this loop? I should add the when I use the technique of sending an email "This URL will only send you an email if the IP address from which you are accessing it is being blocked by Admin Tools. If you are not blocked no email will be sent" I never get an email, so it seems possibly my IP address is not being blocked and something else is happening. This has occurred 8 times today when I can't access my site, and am hoping it is a setting I need to that prevents this from happening.

 

Thank you again!

nicholas
Akeeba Staff
Manager

What is the Reason and Target URL in the Blocked Requests Log for the line which displays your own IP address?

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

timpennington

It says "Admin Query String" for https://finishingandcoating.com/administrator/index.

Thank you.

timpennington

I should add that I have repeatedly used the Secret Administrator URL Parameter feature to gain access; but then it goes back to blocking the IP. It has cycled like that several times.

 

Thank you

nicholas
Akeeba Staff
Manager

This actually does help a lot narrowing it down. What I will tell you below is basically a simplified and immediately actionable form of what I have already documented, plus some notes I have on Joomla itself based on my own experience.

Go to Components, Admin Tools, Web Application Firewall, Configure WAF.

Click on the Basic Features tab.

Set "Browser cookie override for the administrator secret URL parameter" to Enabled.

Click on Save & Close.

This will set a cookie in your browser which prevents you from getting blocked when your session expires due to inactivity.

Speaking of…

Go to System, Setup, Global Configuration.

Click on the System tab.

Set the "Session Lifetime (minutes)" to something higher. For example, 480 sets it to 8 hours.

Click on Save & Close.

It is also a good idea to remember to close all tabs and browser windows showing pages of your site's admin backend when you are done working on the backend of your site, or you're about to step out / do something else for more than 10 minutes. This will prevent you from getting issues related to your session auto-expiring due to inactivity.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

timpennington

Thank you!

The "Browser cookie override for the administrator secret URL parameter" was already set to Enabled, so I set it Disabled and saved it, then Enabled it and saved again.

I also changed the time to 480 minutes.

I then went back in and "Unblocked my IP" and reset the provider file.

Hope this helps, and i appreciate you quick reponse, especially on a weekend.

Update: I was getting hammered by a bot from a specific gmail.com account about 2,000 a day with emails; your component is very effecctive. I still get about 4-5 every other day, and have no clue how he is even getting in to send those, but I can take 4-5 every other day instead of 4,000+ in that time span.

 

Thanks

 

timpennington

Hello Nicholas:

This morning the same situation repeated.

1. Tried to log in to the admin and instead the page redirected to the homepage.

2. When I again tried to go to https://finishingandcoating.com/administrator, I received the error message that "We have detected suspicious activity from your IP address ..."

3. When I went to the home page, the same message of "We have detected suspicious activity from your IP address ..."

 

I then changed the file to provide-disable to gain access; I saw in the Blocked Request Log that the issue was "Admin Query String" to https://finishingandcoating.com/administrator/, which seems to be the same problem I have been having. I did check from our previous notes, and the "Behind Load Balancer" is set to "Yes."

 

Is there anything else I should check to prevent my IP from being blocked again and having to go through the rest of the stages again?

 

Thank you again for all your help.

 

nicholas
Akeeba Staff
Manager

It is also a good idea to remember to close all tabs and browser windows showing pages of your site's admin backend when you are done working on the backend of your site, or you're about to step out / do something else for more than 10 minutes. This will prevent you from getting issues related to your session auto-expiring due to inactivity.

Nicholas K. Dionysopoulos

Lead Developer and Director

🇬🇷Greek: native 🇬🇧English: excellent 🇫🇷French: basic • 🕐 My time zone is Europe / Athens
Please keep in mind my timezone and cultural differences when reading my replies. Thank you!

Support Information

Working hours: We are open Monday to Friday, 9am to 7pm Cyprus timezone (EET / EEST). Support is provided by the same developers writing the software, all of which live in Europe. You can still file tickets outside of our working hours, but we cannot respond to them until we're back at the office.

Support policy: We would like to kindly inform you that when using our support you have already agreed to the Support Policy which is part of our Terms of Service. Thank you for your understanding and for helping us help you!