<div dir="ltr"><div class="gmail_default" style="font-family:georgia,serif">As root, I added IP addresses that the firewall should reject immediately. Getting status showed that they had been added to the reject list.</div><div class="gmail_default" style="font-family:georgia,serif">However, they are still showing up in BlueOnyx with attempts to login as root.<br></div><div class="gmail_default" style=""><br><font face="georgia, serif">For example, I used</font><br><p class="MsoNormal" style="margin:0in 0in 1pt"><font face="trebuchet ms, sans-serif">firewall-cmd --permanent --add-rich-rule="rule family='ipv4' source
address='61.177.172.191' reject"<br></font><font face="Palatino Linotype, serif">on one IP address, but just today, someone/something on that IP tried to login almost 800 times.</font></p><p class="MsoNormal" style="font-family:"Palatino Linotype",serif;margin:0in 0in 1pt">(That IP is registered in <span style="font-size:9pt">Lianyungang city, </span><span style="font-size:12px">Jiangsu province, Communist China.)</span></p><p class="MsoNormal" style="font-family:"Palatino Linotype",serif;margin:0in 0in 1pt"><br></p><p class="MsoNormal" style="font-family:"Palatino Linotype",serif;margin:0in 0in 1pt">Was that not the correct command to use to force rejection of that IP address in AlmaLinux/BlueOnyx?</p></div><div><br></div>-- <br><div dir="ltr" class="gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><div dir="ltr"><div><font face="georgia, serif">Eduard Qualls</font></div><div><font face="georgia, serif"><i><a href="http://www.eduardqualls.com" target="_blank">www.eduardqualls.com</a></i></font></div><span></span><img src="https://ci3.googleusercontent.com/mail-sig/AIorK4z0oljRVkBvcSDfv067hMZzctSm8q-bW8L9f1JSi0LAdDxNeg6trzzFPKC3niTuUnusjEUTM2Ue2BtyYTAtPr0Df55yMZf-5E7bfl3naQ"><br></div></div></div></div></div></div></div></div></div>