It is very simple. When enabling the name-based brute force routine, I am locked out. File not found. I am at a loss how this routine is enabled. It is not enable to the .htaccess file.
The cookie-based brute force routine also does not seem to be operative. But it does not prevent me from logging in. It simply leads me to the usual WP–login.php routine.
Repeating, every single time I use the name-based brute force routine I am locked out. The only way to recover is through the back door, deleting the entire plug-in. That allows me to login once again. I don’t know whether this is a permission-based problem. All my directories are CHMOD apache.
It has worked in the past when used InMotionHosting VPS server. But does not work with any Amazon web service instance.